logo

AI-Assisted Phishing Campaign Harvesting Victim Data

ID: 92c10c81-18ba-5108-9756-c38df5dea4d2

STIX ID: report--92c10c81-18ba-5108-9756-c38df5dea4d2

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-03-16

Date Updated: 2026-07-16

...
...

Executive Summary — Cyble Research & Intelligence Labs identified an active, scalable phishing campaign hosted on edgeone.app that social-engineers victims into granting camera, microphone, and contact permissions; client-side JavaScript then captures images, video, audio, device telemetry, and location and exfiltrates these artifacts via the Telegram Bot API. The report details the attack chain, targeted brands and lures, indicators of potential AI-assisted code generation, business impacts (identity fraud, KYC bypass, extortion, targeted social engineering), and recommended mitigations such as restricting camera permissions, monitoring traffic to api.telegram.org, deploying browser security controls, and domain monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.