New Attack Wave Sees Threat Actors Masquerading as Popular Brands to Spread Malware
ID: 974094f4-12bc-5d99-80c0-e29ea47d9c08
STIX ID: report--974094f4-12bc-5d99-80c0-e29ea47d9c08
Feed Name: Cyber Press
This report details a sophisticated smishing campaign that spoofs trusted brands by inserting them before the '@' in URLs, uses aged domains (6–12 months) to build reputation before short-lived activation windows (72–96 hours), and delivers multi-stage malware including credential-harvesters and a RAT via APKs or signed executables. Attackers employ redirect chains, CDN-hosted C2, TLS with self-signed certificates chained to legitimate roots, and runtime checks to evade detection; recommended mitigations include improved URL parsing, mobile threat defense, long-press link inspections, and browser isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
