A new Teams vishing campaign called Spring Ring used fake IT support calls to trick employees into installing remote-access ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
TerminalFix is a new ClickFix campaign that tricks users into running PowerShell commands and turns infected Windows PCs into network pivots.
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
An advanced malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with ...
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login ...
A previously undocumented malware loader, dubbed SynkLoader, that combines Python, C#, and native C++ components to evade ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
A module is a mechanism for grouping functions, settings, and other elements for reuse. By organizing frequently used processes into modules, it becomes easier to call the same functionality from ...
A sophisticated malware campaign is quietly targeting Korean users through a well-crafted chain of deception. Threat actors are using innocent-looking shortcut files, built-in Windows tools, and a ...
Modular, opt-in AI agent instructions for any codebase. AIM provides a curated collection of instruction modules that work with all popular AI coding agents including GitHub Copilot, Claude, Cursor, ...