Tag

Vishing

All articles tagged with #vishing

Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft
technology1 month ago

Executive Vishing Campaign Cracks Microsoft 365 with MFA Token Theft

Threat actors impersonating IT desk staff use vishing and an adversary-in-the-middle token theft flow to harvest Microsoft 365 credentials and MFA approvals, enabling access to authenticated sessions via proxy replay; they exfiltrate data from SharePoint, OneDrive, Exchange, and Box, targeting executives across sectors. Defenses include phishing-resistant MFA, Conditional Access, restricting SharePoint data access, and employee training on vishing risks.

AI-Driven Vishing Attacks Target Hedge Funds, Exposing Impersonation Risk
technology2 months ago

AI-Driven Vishing Attacks Target Hedge Funds, Exposing Impersonation Risk

Bloomberg reports AI-powered voice phishing targeted major hedge funds, including Citadel and Two Sigma, with attackers using AI-generated voices to bypass security; Two Sigma says it detected the attack in time, while other firms did not immediately respond to comment, highlighting the growing risk of AI-enabled impersonation and the need for stronger safeguards in AI systems.

AI-Voice Vishing Targets Major Hedge Funds on Wall Street
business2 months ago

AI-Voice Vishing Targets Major Hedge Funds on Wall Street

Major hedge funds including Point72, Millennium, Two Sigma, and Citadel were targeted in a coordinated AI-powered vishing campaign that used voice cloning to try to extract credentials; Two Sigma says it blocked the attempt and no client data was reportedly stolen, while FINRA is coordinating a response. The incident underscores how AI lowers the barrier for large-scale social-engineering attacks across financial firms.

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America
security2 months ago

Teams Impersonations Fuel Chaos Ransomware Deployments Across North America

Sophos warns of STAC4749, a vishing campaign in which external Microsoft Teams calls impersonate IT staff to gain remote access, deploying backdoors and culminating in Chaos ransomware across dozens of North American organizations (Canada ~50%, US ~45%). Attackers used fake IT domains under the .top TLD, relied on Quick Assist or RemSupp, then PowerShell to install persistence and remote access tools like DWAgent/AnyDesk, with RDP used for lateral movement. Ransomware encrypts files and may accompany data theft; Chaos-as-a-service is linked to Conti offshoots. The techniques evolved to evade detection; no confirmed link to MuddyWater.

Google Addresses Security Warnings Amid Hacker Threats and Data Breaches
technology1 year ago

Google Addresses Security Warnings Amid Hacker Threats and Data Breaches

ShinyHunters, a cybercrime group known for data breaches and now employing voice-based social engineering tactics like vishing, has targeted major companies including Salesforce, affecting millions of users. The group has links with other hacking groups and is involved in selling stolen data and offering ransomware services. Protecting against such attacks involves vigilance, employee training, and enhanced security measures like multi-factor authentication. The rise of AI-generated deepfakes makes these scams more sophisticated and harder to detect.

FakeCall Malware Exploits Androids for Banking Scams
mobile-security-financial-fraud1 year ago

FakeCall Malware Exploits Androids for Banking Scams

A new variant of the FakeCall Android malware has been discovered, using voice phishing techniques to deceive users into divulging personal information. This sophisticated malware can intercept and hijack calls, redirecting them to fraudulent numbers controlled by attackers, while mimicking legitimate banking interfaces. It exploits accessibility services to gain control over devices, capturing sensitive data and performing unauthorized actions. The malware's evolution highlights ongoing challenges in mobile security, despite efforts to enhance defenses against such threats.

"American Companies' Vulnerability Exposed: Lessons from the MGM Cyber Attack"
cybersecurity3 years ago

"American Companies' Vulnerability Exposed: Lessons from the MGM Cyber Attack"

MGM Resorts experienced a cyberattack that disrupted its systems, including hotel room digital keys and slot machines. The attack was believed to be carried out by a group known as Scattered Spider, specializing in social engineering techniques like vishing. The hackers impersonated an employee in a phone call to MGM's IT help desk to gain access to the systems. The group claims to have stolen and encrypted MGM's data and is demanding a ransom in crypto. Another casino chain, Caesars Entertainment, also experienced a cyberattack around the same time. Vishing, a combination of voice and phishing, is a growing cybersecurity threat that targets human vulnerabilities. Organizations are urged to strengthen their defenses against social engineering attacks and provide better training to employees.