#cybercrime

114 posts · Last used 8d

Quiz time: which of these domains is impersonating Apple? quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started. What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS. This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike. #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
0
0
9
0
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling. Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains. The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar. The tunnel itself is answering with TXT records like: ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz" As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this. We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn: We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly. Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you. ⛔ validx[.]shop ⛔ cordkit[.]online ⛔ zenithly[.]best ☠️ 95[.]179[.]159[.]229 #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
16
0
18
0
Exclusive, breaking: Dutch Police Arrest "Reformed" Hacker in ShinyHunters investigation Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect’s arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. https://krebsonsecurity.com/2026/09/dutch-police-arrest-reformed-hacker-in-shiny-hunters-investigation/ #shinyhunters #cybercrime
75
8
86
2
#LLRX #CyberSecurity @bespacific@newsie.social Pete Recommends – Weekly highlights on cyber security issues, September 26, 2026 Five highlights from this week: Despite upgrades, #IRS cyber program still ‘not effective,’ watchdog says; Mobile driver's licenses now widely accepted at Login-dot-gov for ID verification; Even a #VPN Can’t Protect You From This Browser Security Flaw; Bad Connection – Uncovering Global Telecom Exploitation by Covert Surveillance Actors; and Google #Gemini #AI model hacks three ot Posted in: AI, #cybercrime Cybersecurity, Federal Legislative Research, Legal Research, #Privacy Social Media https://www.llrx.com/2026/09/pete-recommends-weekly-highlights-on-cyber-security-issues-september-26-2026/
0
0
3
0
Can we please charge these horrible people with a crime already? It really is getting unbearably dumb when they blame “AI” for their negligence. #ai #cybercrime #felony “Australia launches urgent review after OpenAI programme hacks government health portal” https://www.bbc.com/news/live/cvgl73pxgndwt
1
0
3
0
Solicitar senha. Solicitar token. Token inválido. Aguardar. That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time. Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one. No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like. Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal. Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other. Phishing domains: ⛔️ pactualapp[.]com ⛔️ pactualpj[.]com ⛔️ pactual[.]live ⛔️ ativarbia[.]net ⛔️ ativarbia[.]com ⛔️ pactualapp[.]live ⛔️ centraldecancelamentos[.]pt ⛔️ verificador-cliente[.]live ⛔️ ativador-login[.]click #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
1
0
1
0
Replying to
Reward: You've received a Depreciated Security Budget Trophy — a participation medal for the age of discount ransomware. https://www.msspalert.com/news/ai-lowers-cybercrime-costs-increasing-ransomware-attacks #Ransomware #CyberSecurity #AI #Cybercrime #ThreatIntelligence #EconomicsOfEvil (3/3)
0
0
0
0
Today's story is the result of an ungodly amount of research, and I am very glad to finally be able to share it with you. Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.” The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing. https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/ #cybercrime #cybersecurity #arrest #teamcp
325
15
286
5
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
0