// PHISHING

// ФІШИНГ

2 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Fake Google Security site uses PWA app to steal credentials, MFA codes

An active phishing campaign is targeting users with a fake Google Account security page that deploys a progressive web app (PWA) to steal credentials, MFA codes, and cryptocurrency wallet addresses while using victims' browsers as proxies. This describes a real, ongoing attack targeting actual victims with specific malicious capabilities.

SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks

The Scattered LAPSUS$ Hunters (SLH) cybercrime group is actively recruiting women to conduct vishing (voice phishing) attacks against IT help desks, offering $500-$1,000 per call. This represents an active social engineering campaign targeting organizational security infrastructure.