ZeroHour

Search: “network monitoring”

4 stories in the last 7d

Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

Group-IB attributes large-scale smishing using the JWR real-time phishing kit to the Smishing Triad's Outsider cluster, harvesting card data, OTPs, and bank credentials.

Group-IB attributes a large-scale SMS phishing campaign to Outsider, an operator sub-cluster within the Smishing Triad phishing-as-a-service ecosystem, using a kit dubbed JWR. The Vue 2-based platform maintains real-time WebSocket communication with operators, enabling them to adapt pages live and harvest roughly 70 PII fields, card data, PINs, OTPs, identity document images, and digital wallet credentials via a dedicated PayPal sub-funnel. Unit 42 previously tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024. Defenders can hunt for /api/open/ endpoints, /webSocket/QT/ paths, JWR-prefixed storage artifacts, and a hard-coded WebSocket token.

GBHackersupdated · 1d agofirst · 1d agoPhishing & fraud in the wild 2 sources

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

Rapid7 analyzes how fraud marketplaces are fragmenting into specialized shops after larger marketplaces were dismantled, aided by new MITRE F3 framework

Rapid7 reports a shift from large known fraud marketplaces to a fragmented environment of smaller specialized storefronts such as Xleet, Blackpass, Infodig, and Styx, operating across dark web channels, Telegram, and P2P options. These Fraud-as-a-Service shops sell stolen accounts, PII, synthetic identity generation, infrastructure, and money laundering support, supporting schemes like business email compromise. MITRE's Fraud Fighting Framework (F3), introduced in early 2026, aims to help security teams prioritize monitoring of fraud TTPs, particularly account takeover techniques. Fraud damages are anticipated to approach hundreds of billions of USD.

Rapid7 Blog · 6d agoPhishing & fraud

The sexy AI-powered dating app scams are here

Anthropic exposed a network of roughly 28 AI-driven dating apps using autonomous personas and gig workers to defraud paying users.

Anthropic threat intelligence uncovered a fraud network of around 28 dating apps after a prepaid account sent over 100,000 Claude API requests daily, with most chats run by autonomous AI personas and no human agent. Researchers Matthew Gore-Kormanik and Anthropic's Chris Cronbaugh documented apps including Dora, Romi, and Doni, which monetize conversations via coins; gig workers were hired only to pass liveness checks and select pregenerated replies. An operations manual written in Chinese was found inside the Doni app, and Anthropic published findings in its September 2026 AI misuse report.

The Verge · AI · 23h agoPhishing & fraud in the wild

Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casinonew

ADEX uncovered a hacked Thai college domain serving casino pages through real Google search redirects, part of a global campaign compromising government and education sites.

Anti-fraud platform ADEX found a casino-themed page planted on the compromised km.chpc.ac.th domain in Thailand's educational .ac.th zone, which Google indexed and ranked first to redirect users to illegal online gambling. The scheme achieved full ad cloaking without deploying any cloaking code by chaining a genuine Google results page and a third-party redirect. The same domain-borrowing tactic is tracked globally: Thailand reports roughly 30 million gambling URLs across about 1,000 public-sector sites, Indonesia blocked 683 government and education sites, and Netcraft found an underground market selling access to more than 15,000 compromised .gov, .edu and ccTLD domains. ADEX argues Google's site reputation abuse policy does not cover institutions that are hijacked without their knowledge.

Cyber Security News · 31m agoPhishing & fraud in the wild