Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Cyberint

Phishing operators abuse bank APIs to improve phishing TTPs

True Login phishing kits are continuously being developed by threat actors to improve their TTPs in luring victims. By using true login kits, the phishing operators have a higher chance of making potential victims believe they are logging into the real website. True login kit developers are abusing publicly available APIs of the banking company to be able to query login information to be shown to potential victims, in turn luring the victim even further into the operations.

Webinar: Preventing Privacy and Cybersecurity Breaches

Check out this webinar to gain a deeper understanding of how to prevent privacy and cybersecurity breaches and ensure business continuity in a zero trust world. The webinar is hosted by Natali Adison, Technology, Data Protection & Cybersecurity attorney and Reuben Braham, VP Marketing at Cyberint.

Masslogger Stealer

Cyberint Research observed several unsolicited malicious email (malspam) campaigns in August 2021 through which Masslogger was delivered. First noticed around April 2020, Masslogger is a popular.NET credential stealer used to gather credentials from victims for various applications, and is readily available to purchase on cybercriminal forums for around $100 (US).