Researchers have uncovered a large-scale phishing campaign targeting organizations across the United States through fake event invitation emails and websites. The operation, active since late 2025, uses convincing social engineering techniques to trick victims into revealing login credentials, submitting one-time passwords, or unknowingly installing remote access software. What makes this campaign especially dangerous is the professional appearance of the phishing pages and the consistent structure used across hundreds of malicious domains. The attackers design websites that closely resemble legitimate invitation or event management platforms. Victims are first directed through a CAPTCHA verification page, often imitating trusted security services such as Cloudflare, which helps reduce suspicion. After completing the CAPTCHA, users are shown a fake invitation page requesting them to sign in with accounts such as Google, Microsoft, Yahoo, or AOL. Once credentials are entered, the victim is presented with a false “Incorrect Password” message, encouraging them to re-enter their password and increasing the chances of capturing accurate login information. In some cases, the phishing process also includes forms that request verification codes, allowing attackers to bypass multi-factor authentication protections. Other versions of the campaign automatically deliver remote monitoring and management tools, giving attackers silent access to organizational systems. The campaign mainly targets industries including education, banking, healthcare, government, and technology because these sectors rely heavily on email systems and remote administration tools. Researchers also detected evidence of automation and potential AI-generated content, allowing cybercriminals to quickly produce and deploy phishing websites at minimal expense. Despite the campaign’s sophistication, researchers identified repeated infrastructure patterns across domains, including shared file paths and page layouts. These similarities provide valuable detection opportunities for cybersecurity teams, who can monitor suspicious web requests and investigate unexpected remote access software installations to reduce the risk of compromise.
Cybersecurity researchers have identified an ongoing malware campaign distributing the VIP Keylogger malware through phishing emails and malicious attachments. The campaign primari...
ClearFake malware operators have introduced a new tactic by abusing Binance Smart Chain (BSC) Testnet infrastructure to host and retrieve malicious content, further advancing block...
Roundcube Webmail administrators are being advised to urgently patch their systems after the disclosure of several high-risk security vulnerabilities affecting both the 1.6.x and 1...