Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Netcraft

@Netcraft@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Netcraft provides powerful phishing detection, cybercrime disruption, and website takedown solutions to the world's largest organizations.

11 Followers
18 Following
17 Posts
Joined August 19, 2025
Netcraft.com:
Netcraft.com
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

RE: @BleepingComputer@infosec.exchange

New breaking research from us 👇

And you can read more here https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat

infosec.exchange
1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

Observed in the wild: A phishing page that requests getUserMedia() permissions under the guise of a Visa Secure payment check, then silently captures frames from the front-facing camera every 2 seconds and POSTs them to a Telegram bot via hardcoded bot token in client-side JS.

A second variant records 20 stills + 10 short video clips before exfil. The Telegram credentials are exposed in the page source — an operational weakness that creates a disruption opportunity.

Full code-level analysis by Ivan Khamenka:

https://www.netcraft.com/blog/how-camera-first-phishing-turns-payment-verification-into-surveillance

#infosec #phishing #threatintel #javascript

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data
netcraft.com

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data

A newly observed phishing campaign impersonates payment verification to harvest selfies, videos, location data, and device information. Learn how camera-first phishing turns browser permissions into a powerful collection channel.

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

EvilTokens abuses OAuth device code flow to phish credentials without ever rendering a fake login page.

The victim authenticates through a legitimate Microsoft prompt. The attacker gets the token. No credential harvest, no spoofed UI — just a device code the victim was socially engineered into approving.

Netcraft's analysis covers the full attack chain including GhostPairing, a variant that pairs attacker-controlled devices mid-session.

Detailed breakdown with campaign infrastructure observations: https://www.netcraft.com/blog/eviltokens-and-oauth-abuse

#infosec #phishing #OAuth #threatintel

netcraft.com
1
0
2
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

🚨 NEW THREAT INTEL REPORT: A football sponsorship isn’t always what it seems. ⚽
Our latest research uncovers how Felix Markets used sports to launder legitimacy for a fraudulent investment platform.

https://www.netcraft.com/blog/fake-investment-platform-reputation-laundering-felix-markets

#ReputationLaundering #BrandProtection #ScamAlert

netcraft.com
1
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

📞 “Hello, this is your bank…”

No it’s not.

Learn how PNC’s team spots these calls before they reach customers.
💡 Webinar Nov 17 – Reserve your spot:

https://www.netcraft.com/lp/disrupt-phone-fraud-webinar

#Fraud #Cybersecurity #BrandProtection

netcraft.com
1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
Browser-in-the-Middle phishing has evolved. Bluekit uses a session replay library (rrweb) to stream a live, interactive login page from the attacker's browser to the victim's. It looks and behaves exactly like the real thing — because it is. New research from our team: https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat #phishing #PhishingKits
netcraft.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
How financial institutions should be preparing for the upcoming new #Scams Prevention Framework in #Australia https://www.netcraft.com/blog/australia-scams-prevention-framework-what-the-new-obligations-mean-for-banks
netcraft.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

Brand impersonation is being used at scale for casino affiliate fraud.

Ads on #Meta/#TikTok claim a well-known brand "launched" a slots product. The landing page mimics an app store listing. Tapping "Install" registers a Progressive Web App that opens a casino endpoint through an affiliate link, title bar still showing the impersonated brand's name/icon.

We've observed this across UK financial brands, retail (Tesco, Amazon), and streaming (Netflix), plus DE/ES-language variants.

IOCs, domain patterns, and affiliate CPA figures ($50–$350/depositing player) in the full post: https://www.netcraft.com/blog/branded-gambling-campaigns-how-scammers-are-exploiting-trusted-brands

infosec.exchange

Infosec Exchange

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

RE: @BleepingComputer@infosec.exchange

Proud to support NCSC’s proactive notifications pilot. External scanning helps surface exposed services and known vulnerabilities so organizations can remediate faster. Important initiative outlined here.

infosec.exchange
0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

Attackers are leveraging behavioral science to shape their campaigns.
Netcraft expects this to intensify in 2026, making intent detection just as important as artifact detection.

https://vmblog.com/archive/2025/11/19/five-cybersecurity-predictions-for-the-year-ahead.aspx

#BrandProtection #ThreatIntelligence #Phishing #Infosec

vmblog.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

Google has filed suit against a Chinese-based phishing-kit platform behind toll-road & delivery scams. Meanwhile our team at Netcraft uncovered 17,500+ domains targeting 316 global brands.

Read how PhaaS is going industrial: https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands

netcraft.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 13mo ago

🚨NEW RESEARCH🚨

Attackers don’t always need zero-days. Sometimes, all it takes is a single character.
Our researchers recently uncovered a phishing wave abusing the Japanese Hiragana character “ん” – a lookalike that resembles a forward slash or Latin “n.” By inserting it into domain names, attackers are creating URLs that appear legitimate at a glance but redirect victims to credential harvesters, fake crypto wallets, and malware downloads.

Our investigation traced more than 600 malicious domains leveraging this technique.

Why it matters:
Unicode confusion lets these domains slip past regex filters and automated scanners. Punycode encoding makes them DNS-valid and browser-friendly.

The tactic spreads fast, beyond crypto into travel, enterprise, and education. This is a textbook example of attackers weaponizing subtlety.

👉 Read our full analysis here: https://www.netcraft.com/blog/down-the-hiragana-hole-uncovering-a-new-wave-of-lookalike-domains

#BrandProtection #Cybersecurity #ThreatIntelligence

netcraft.com
0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
Fragmented brand protection monitoring creates blind spots: threat actors reuse domains, hosting, phone numbers, and accounts across channels, so takedowns on one surface don't stop the campaign elsewhere. Our new post covers why channel-centric monitoring breaks containment and what cross-channel correlation looks like in practice. https://www.netcraft.com/blog/brand-protection-monitoring
netcraft.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Kelly Bissell (former CVP, Fraud & Abuse, Microsoft) pushes back on headline-driven threat prioritization: nation-state attribution generates press coverage, but fraud is what actually costs organizations money. Full discussion in IWG Rewind, our on-demand series of exclusive talks. #Fraud #InfoSec #CISO
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Netcraft's Luke Wood examines how AI-assisted #VibeCoding platforms are being abused to build phishing infrastructure. Inconsistent KYC checks, easily bypassed content filters, and free-tier abuse are enabling low-skill threat actors to generate functional credential-harvesting pages with no development experience. One tracked platform's abuse reports grew from <250/month (Jan 2025) to 4,000+/month (Oct 2025). netcraft.com/blog/rise-of-ai-vibe-coding-and-new-cyber-threats
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Our recent research tested 2,905 AI-generated responses to natural-language queries about brand login pages across #ChatGPT, #Copilot, #Gemini, and #perplexity 1.7% of responses contained malicious links; of the 20,706 total links returned, 0.28% pointed to attacker-controlled infrastructure rather than parked or hallucinated domains. This marks a shift from 2025 findings, where the primary risk was #AI citing unclaimed domains. Full methodology and case examples (including a Wells Fargo phishing page served via Copilot) here: https://www.netcraft.com/blog/threat-actors-are-finding-their-way-into-your-ai-summaries
netcraft.com
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3w ago
New analysis: In 2026, 64% of Netcraft takedowns and disruptions relied on proprietary intelligence that open-source monitoring would not have surfaced on its own — cybercrime reporting networks, internet telemetry, proxy infrastructure reaching geofenced/cloaked content, and historical classification data. The underlying problem is that OSINT sources (DNS records, CT logs, public threat feeds) are, by definition, visible to everyone — including the threat actors. More than 95% of phishing victim traffic occurs within 20 hours of detection, so detection speed measured in days rather than minutes represents a materially different outcome, not a slower version of the same one. We've got a breakdown of the visibility gap, evidence requirements for takedown, and the questions worth asking any DRP vendor on our blog: https://www.netcraft.com/blog/attackers-dont-publish-an-asset-inventory #infosec #threatintel #phishing
Netcraft: Attackers don
netcraft.com

Netcraft: Attackers don

Why public threat feeds aren

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 01:59:40 UTC