Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Netcraft

@Netcraft@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Netcraft provides powerful phishing detection, cybercrime disruption, and website takedown solutions to the world's largest organizations.

11 Followers
18 Following
17 Posts
Joined August 19, 2025
Netcraft.com:
Netcraft.com
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago

RE: @BleepingComputer@infosec.exchange

New breaking research from us 👇

And you can read more here https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat

BleepingComputer: "The Bluekit phishing-as-a-service platform contin…" - Infosec Exchange

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago

Observed in the wild: A phishing page that requests getUserMedia() permissions under the guise of a Visa Secure payment check, then silently captures frames from the front-facing camera every 2 seconds and POSTs them to a Telegram bot via hardcoded bot token in client-side JS.

A second variant records 20 stills + 10 short video clips before exfil. The Telegram credentials are exposed in the page source — an operational weakness that creates a disruption opportunity.

Full code-level analysis by Ivan Khamenka:

https://www.netcraft.com/blog/how-camera-first-phishing-turns-payment-verification-into-surveillance

#infosec #phishing #threatintel #javascript

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data

A newly observed phishing campaign impersonates payment verification to harvest selfies, videos, location data, and device information. Learn how camera-first phishing turns browser permissions into a powerful collection channel.

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago

EvilTokens abuses OAuth device code flow to phish credentials without ever rendering a fake login page.

The victim authenticates through a legitimate Microsoft prompt. The attacker gets the token. No credential harvest, no spoofed UI — just a device code the victim was socially engineered into approving.

Netcraft's analysis covers the full attack chain including GhostPairing, a variant that pairs attacker-controlled devices mid-session.

Detailed breakdown with campaign infrastructure observations: https://www.netcraft.com/blog/eviltokens-and-oauth-abuse

#infosec #phishing #OAuth #threatintel

1
0
2
0
Open post
Netcraft @Netcraft@infosec.exchange
· 9mo ago

🚨 NEW THREAT INTEL REPORT: A football sponsorship isn’t always what it seems. ⚽
Our latest research uncovers how Felix Markets used sports to launder legitimacy for a fraudulent investment platform.

https://www.netcraft.com/blog/fake-investment-platform-reputation-laundering-felix-markets

#ReputationLaundering #BrandProtection #ScamAlert

1
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

📞 “Hello, this is your bank…”

No it’s not.

Learn how PNC’s team spots these calls before they reach customers.
💡 Webinar Nov 17 – Reserve your spot:

https://www.netcraft.com/lp/disrupt-phone-fraud-webinar

#Fraud #Cybersecurity #BrandProtection

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Browser-in-the-Middle phishing has evolved. Bluekit uses a session replay library (rrweb) to stream a live, interactive login page from the attacker's browser to the victim's. It looks and behaves exactly like the real thing — because it is. New research from our team: https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat #phishing #PhishingKits
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
How financial institutions should be preparing for the upcoming new #Scams Prevention Framework in #Australia https://www.netcraft.com/blog/australia-scams-prevention-framework-what-the-new-obligations-mean-for-banks
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago

Brand impersonation is being used at scale for casino affiliate fraud.

Ads on #Meta/#TikTok claim a well-known brand "launched" a slots product. The landing page mimics an app store listing. Tapping "Install" registers a Progressive Web App that opens a casino endpoint through an affiliate link, title bar still showing the impersonated brand's name/icon.

We've observed this across UK financial brands, retail (Tesco, Amazon), and streaming (Netflix), plus DE/ES-language variants.

IOCs, domain patterns, and affiliate CPA figures ($50–$350/depositing player) in the full post: https://www.netcraft.com/blog/branded-gambling-campaigns-how-scammers-are-exploiting-trusted-brands

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 9mo ago

RE: @BleepingComputer@infosec.exchange

Proud to support NCSC’s proactive notifications pilot. External scanning helps surface exposed services and known vulnerabilities so organizations can remediate faster. Important initiative outlined here.

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 9mo ago

Attackers are leveraging behavioral science to shape their campaigns.
Netcraft expects this to intensify in 2026, making intent detection just as important as artifact detection.

https://vmblog.com/archive/2025/11/19/five-cybersecurity-predictions-for-the-year-ahead.aspx

#BrandProtection #ThreatIntelligence #Phishing #Infosec

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

Google has filed suit against a Chinese-based phishing-kit platform behind toll-road & delivery scams. Meanwhile our team at Netcraft uncovered 17,500+ domains targeting 316 global brands.

Read how PhaaS is going industrial: https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 12mo ago

🚨NEW RESEARCH🚨

Attackers don’t always need zero-days. Sometimes, all it takes is a single character.
Our researchers recently uncovered a phishing wave abusing the Japanese Hiragana character “ん” – a lookalike that resembles a forward slash or Latin “n.” By inserting it into domain names, attackers are creating URLs that appear legitimate at a glance but redirect victims to credential harvesters, fake crypto wallets, and malware downloads.

Our investigation traced more than 600 malicious domains leveraging this technique.

Why it matters:
Unicode confusion lets these domains slip past regex filters and automated scanners. Punycode encoding makes them DNS-valid and browser-friendly.

The tactic spreads fast, beyond crypto into travel, enterprise, and education. This is a textbook example of attackers weaponizing subtlety.

👉 Read our full analysis here: https://www.netcraft.com/blog/down-the-hiragana-hole-uncovering-a-new-wave-of-lookalike-domains

#BrandProtection #Cybersecurity #ThreatIntelligence

How Hiragana ‘ん’ Is Fooling Users in Phishing Attacks | Netcraft Threat Research

How Hiragana ‘ん’ Is Fooling Users in Phishing Attacks | Netcraft Threat Research

Cybercriminals are exploiting the Japanese Hiragana character “ん” in phishing domains to mimic trusted sites like Booking.com, Microsoft, and crypto wallets. Learn how this homoglyph trick evades detection and what defenders can do to stay ahead.

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Fragmented brand protection monitoring creates blind spots: threat actors reuse domains, hosting, phone numbers, and accounts across channels, so takedowns on one surface don't stop the campaign elsewhere. Our new post covers why channel-centric monitoring breaks containment and what cross-channel correlation looks like in practice. https://www.netcraft.com/blog/brand-protection-monitoring
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 1mo ago
Kelly Bissell (former CVP, Fraud & Abuse, Microsoft) pushes back on headline-driven threat prioritization: nation-state attribution generates press coverage, but fraud is what actually costs organizations money. Full discussion in IWG Rewind, our on-demand series of exclusive talks. #Fraud #InfoSec #CISO
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 1mo ago
Netcraft's Luke Wood examines how AI-assisted #VibeCoding platforms are being abused to build phishing infrastructure. Inconsistent KYC checks, easily bypassed content filters, and free-tier abuse are enabling low-skill threat actors to generate functional credential-harvesting pages with no development experience. One tracked platform's abuse reports grew from <250/month (Jan 2025) to 4,000+/month (Oct 2025). netcraft.com/blog/rise-of-ai-vibe-coding-and-new-cyber-threats
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 1mo ago
Our recent research tested 2,905 AI-generated responses to natural-language queries about brand login pages across #ChatGPT, #Copilot, #Gemini, and #perplexity 1.7% of responses contained malicious links; of the 20,706 total links returned, 0.28% pointed to attacker-controlled infrastructure rather than parked or hallucinated domains. This marks a shift from 2025 findings, where the primary risk was #AI citing unclaimed domains. Full methodology and case examples (including a Wells Fargo phishing page served via Copilot) here: https://www.netcraft.com/blog/threat-actors-are-finding-their-way-into-your-ai-summaries
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 5d ago
New analysis: In 2026, 64% of Netcraft takedowns and disruptions relied on proprietary intelligence that open-source monitoring would not have surfaced on its own — cybercrime reporting networks, internet telemetry, proxy infrastructure reaching geofenced/cloaked content, and historical classification data. The underlying problem is that OSINT sources (DNS records, CT logs, public threat feeds) are, by definition, visible to everyone — including the threat actors. More than 95% of phishing victim traffic occurs within 20 hours of detection, so detection speed measured in days rather than minutes represents a materially different outcome, not a slower version of the same one. We've got a breakdown of the visibility gap, evidence requirements for takedown, and the questions worth asking any DRP vendor on our blog: https://www.netcraft.com/blog/attackers-dont-publish-an-asset-inventory #infosec #threatintel #phishing
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 14:55:12 UTC