RE: @BleepingComputer@infosec.exchange
New breaking research from us 👇
And you can read more here https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat
Netcraft provides powerful phishing detection, cybercrime disruption, and website takedown solutions to the world's largest organizations.
RE: @BleepingComputer@infosec.exchange
New breaking research from us 👇
And you can read more here https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat
Observed in the wild: A phishing page that requests getUserMedia() permissions under the guise of a Visa Secure payment check, then silently captures frames from the front-facing camera every 2 seconds and POSTs them to a Telegram bot via hardcoded bot token in client-side JS.
A second variant records 20 stills + 10 short video clips before exfil. The Telegram credentials are exposed in the page source — an operational weakness that creates a disruption opportunity.
Full code-level analysis by Ivan Khamenka:
https://www.netcraft.com/blog/how-camera-first-phishing-turns-payment-verification-into-surveillance
EvilTokens abuses OAuth device code flow to phish credentials without ever rendering a fake login page.
The victim authenticates through a legitimate Microsoft prompt. The attacker gets the token. No credential harvest, no spoofed UI — just a device code the victim was socially engineered into approving.
Netcraft's analysis covers the full attack chain including GhostPairing, a variant that pairs attacker-controlled devices mid-session.
Detailed breakdown with campaign infrastructure observations: https://www.netcraft.com/blog/eviltokens-and-oauth-abuse
🚨 NEW THREAT INTEL REPORT: A football sponsorship isn’t always what it seems. ⚽
Our latest research uncovers how Felix Markets used sports to launder legitimacy for a fraudulent investment platform.
https://www.netcraft.com/blog/fake-investment-platform-reputation-laundering-felix-markets
📞 “Hello, this is your bank…”
No it’s not.
Learn how PNC’s team spots these calls before they reach customers.
💡 Webinar Nov 17 – Reserve your spot:
Brand impersonation is being used at scale for casino affiliate fraud.
Ads on #Meta/#TikTok claim a well-known brand "launched" a slots product. The landing page mimics an app store listing. Tapping "Install" registers a Progressive Web App that opens a casino endpoint through an affiliate link, title bar still showing the impersonated brand's name/icon.
We've observed this across UK financial brands, retail (Tesco, Amazon), and streaming (Netflix), plus DE/ES-language variants.
IOCs, domain patterns, and affiliate CPA figures ($50–$350/depositing player) in the full post: https://www.netcraft.com/blog/branded-gambling-campaigns-how-scammers-are-exploiting-trusted-brands
RE: @BleepingComputer@infosec.exchange
Proud to support NCSC’s proactive notifications pilot. External scanning helps surface exposed services and known vulnerabilities so organizations can remediate faster. Important initiative outlined here.
Attackers are leveraging behavioral science to shape their campaigns.
Netcraft expects this to intensify in 2026, making intent detection just as important as artifact detection.
https://vmblog.com/archive/2025/11/19/five-cybersecurity-predictions-for-the-year-ahead.aspx
Google has filed suit against a Chinese-based phishing-kit platform behind toll-road & delivery scams. Meanwhile our team at Netcraft uncovered 17,500+ domains targeting 316 global brands.
Read how PhaaS is going industrial: https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands
🚨NEW RESEARCH🚨
Attackers don’t always need zero-days. Sometimes, all it takes is a single character.
Our researchers recently uncovered a phishing wave abusing the Japanese Hiragana character “ん” – a lookalike that resembles a forward slash or Latin “n.” By inserting it into domain names, attackers are creating URLs that appear legitimate at a glance but redirect victims to credential harvesters, fake crypto wallets, and malware downloads.
Our investigation traced more than 600 malicious domains leveraging this technique.
Why it matters:
Unicode confusion lets these domains slip past regex filters and automated scanners. Punycode encoding makes them DNS-valid and browser-friendly.
The tactic spreads fast, beyond crypto into travel, enterprise, and education. This is a textbook example of attackers weaponizing subtlety.
👉 Read our full analysis here: https://www.netcraft.com/blog/down-the-hiragana-hole-uncovering-a-new-wave-of-lookalike-domains