Error 524 Decoy: Unmasking a Global Smishing Operation Hiding Behind Error Pages


Group-IB researchers expose a large-scale smishing and phishing operation impersonating 260+ brands across 72 countries, using fake Cloudflare error pages, geofencing, and encrypted WebSocket channels for real-time credit card theft.

 

Read more…
Source:  Group IB


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Russian Sandworm hackers pose as Ukrainian telcos to drop malware

    September 19, 2022

    The Russian state-sponsored hacking group known as Sandworm has been observed masquerading as telecommunication providers to target Ukrainian entities with malware. Sandworm is a state-backed threat actor attributed by the US government as part of the Russian GRU foreign military intelligence service. The APT hacking group is believed to have been behind numerous attacks this year, including ...

  • Google, Microsoft can get your passwords via web browser’s spellcheck

    September 17, 2022

    Extended spellcheck features in Google Chrome and Microsoft Edge web browsers transmit form data, including personally identifiable information (PII) and in some cases, passwords, to Google and Microsoft respectively. While this may be a known and intended feature of these web browsers, it does raise concerns about what happens to the data after transmission and how ...

  • Eastern European org hit by second record-smashing DDoS attack

    September 16, 2022

    Akamai says it has absorbed the largest-ever publicly known distributed denial of service (DDoS) attack – an assault against an unfortunate Eastern European organization that went beyond 700 million packets per second. This latest tsunami of traffic hit on Monday, according to the web infrastructure biz, and we’re told the cybercriminals responsible for the earlier record-setting ...

  • CISA Releases Eleven Industrial Control Systems Advisories

    September 15, 2022

    CISA has released eleven (11) Industrial Control Systems (ICS) advisories on September 15, 2022. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS. CISA encourages users and administrators to review the newly released ICS advisories for technical details and mitigations: ICSA-22-258-01 Siemens Mobility CoreShield OWG Software ICSA-22-258-02 Siemens Simcenter Femap, Parasolid ICSA-22-258-03 Siemens RUGGEDCOM ...

  • Webworm: Espionage Attackers Testing and Using Older Modified RATs

    September 15, 2022

    Symantec, by Broadcom Software, has gained insight into the current activities of a group we call Webworm. The group has developed customized versions of three older remote access Trojans (RATs), including Trochilus, Gh0st RAT, and 9002 RAT. At least one of the indicators of compromise (IOCs) observed by Symantec was used in an attack against ...

  • Self-spreading stealer attacks gamers via YouTube

    September 15, 2022

    An unusual malicious bundle (a collection of malicious programs distributed in the form of a single installation file, self-extracting archive or other file with installer-type functionality) recently caught our eye. Its main payload is the widespread RedLine stealer. Discovered in March 2020, RedLine is currently one of the most common Trojans used to steal passwords ...