Cybercriminals Exploit Canadians’ Dependence on Digital Services in Widespread Attacks
ID: 0ea59164-a850-51df-b908-e8edbdf12ab8
STIX ID: report--0ea59164-a850-51df-b908-e8edbdf12ab8
Feed Name: GBHackers
Executive Summary: A large-scale phishing campaign targeting Canadians leverages PayTool phishing-as-a-service to impersonate government services (traffic tickets, CRA), Air Canada, and Canada Post via SMS and malicious ads, using typosquatted domains, shorteners, and fallback infrastructure; researchers observed 70+ domains resolving to IP 198.23.156.130 and payment infrastructure in the 45.156.87.0/24 subnet, while threat actors sell phishing kits and coordinate via Telegram, harvesting PII and banking credentials and advising domain monitoring, DNS/web gateway controls, and public awareness campaigns as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
