New Phishing kit utilises SMS, voice calls

Gone Phishing Banner

Welcome to Gone Phishing, your daily cybersecurity newsletter thatโ€™s airdropping you your cybersecurity supplies on a daily basis ๐Ÿช‚๐ŸŽ๐Ÿ›ก๏ธ

Todayโ€™s hottest cybersecurity news stories:

  • ๐Ÿ’ฑ Crypto traders beware! New Phishing kit utilises SMS, voice calls ๐Ÿ“ฑ

  • ๐Ÿ—ฝ U.S. offers $10 million for info leading to capture of Iranian hacker

  • ๐Ÿ‘€ NSO group Meta its match! Ordered to hand over Pegasus code ๐Ÿฆ„

Hackers: Good luck tackling this tackle box! ๐Ÿ‘€๐ŸŽฃ๐Ÿ’€ Dw, Karmaโ€™ll catch up to them ๐ŸŽถ

๐Ÿšจ Alert: New CryptoChameleon Phishing Threat! ๐ŸฆŽ

๐ŸŽฃ A sophisticated phishing kit, part of an attack cluster dubbed CryptoChameleon, has emerged, targeting mobile users by impersonating login pages of popular cryptocurrency services. This kit enables attackers to gather sensitive information, including usernames, passwords, and even photo IDs, from hundreds of victims, primarily in the United States.

๐ŸŽฏ Targets

Victims include employees of the Federal Communications Commission (FCC), as well as users of cryptocurrency platforms such as Binance, Coinbase, Gemini, and more. Over 100 victims have already fallen prey to this phishing campaign.

๐Ÿ” How It Works

The phishing pages are designed to mimic legitimate login screens and are accessed after completing a CAPTCHA test, thwarting automated analysis tools. The attackers employ a variety of tactics, including unsolicited phone calls and text messages, to lure victims into divulging their credentials.

๐Ÿ” Sophisticated Techniques

The phishing kit allows operators to customise pages in real-time, enhancing the illusion of credibility. Once credentials are entered, attackers prompt victims for two-factor authentication (2FA) codes, which are then captured and used to gain access to online services.

๐Ÿ›ก๏ธ Protection Measures

While the origins of CryptoChameleon remain unclear, cybersecurity experts emphasise the importance of remaining vigilant against such phishing attempts. Users are advised to verify the authenticity of login pages and exercise caution when responding to unsolicited communications.

๐Ÿ”— Links to Other Threats

The tactics employed by CryptoChameleon bear resemblance to those used by other threat groups, indicating potential connections within the cybercriminal ecosystem.

Stay informed and stay safe against evolving cyber threats! ๐Ÿ›ก๏ธ๐Ÿ”

Learn AI in 5 minutes a day. We'll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

Uncle Sam: You can Iran but you canโ€™t hide ๐Ÿ™ˆ๐Ÿ™ˆ๐Ÿ™ˆ

๐Ÿšจ DoJ Strikes Back! Iranian Cyber Villain Nabbed! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ’ป๐Ÿ’ฅ

The U.S. Department of Justice (DoJ) has brought down the hammer on an Iranian cyber culprit, Alireza Shafie Nasab, accusing him of orchestrating a sneaky cyber campaign targeting Uncle Sam and some big-shot private players. Nasab, 39, posed as a cyber whiz working for a company called Mahak Rayan Afraz while pulling off this digital caper, which ran from about 2016 to April 2021.

The Cyber Capers Unveiled! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ”“๐Ÿ’ผ

Using devious spear-phishing tricks and other hacker shenanigans, Nasab and his crew allegedly hacked into over 200,000 devices, many of them housing juicy defence secrets. They even had their own custom app to manage these sneaky spear-phishing campaigns like a cyber ninja.

Hack me once, shame on you ๐ŸŽญ๐Ÿ“ง๐Ÿ‘พ

One time, they infiltrated an email account of a defence bigwig, then used it to create fake accounts and send more sneaky emails to folks at other defence companies and consulting firms. They also played some sneaky social engineering games, pretending to be other people, usually women, to fool their victims into downloading malware onto their computers.

Hack me twice, shame on me ๐Ÿšจ๐Ÿ’ธ๐Ÿ‘€

Nasab is accused of sneaking around to get all the tech stuff needed for the caper by using a stolen identity to register servers and email accounts. The DoJ is throwing the book at him, charging him with all sorts of cyber crimes. If heโ€™s found guilty, Nasab could be looking at a whopping 47 years behind bars. Uncle Sam is so keen on getting him that theyโ€™re offering up to $10 million to anyone who can help track him down.

IRGC's Digital Dilemma! ๐Ÿ›ก๏ธ๐Ÿค”๐ŸŒ

Moreover, Nasab's supposed company, Mahak Rayan Afraz (MRA), was flagged by Meta in 2021 for having ties to the Islamic Revolutionary Guard Corps (IRGC), Iran's armed force. This IRGC-linked gang has been caught red-handed before, pulling off social engineering stunts, like pretending to be an aerobics instructor on Facebook to trick an aerospace defence worker into downloading malware.

Cyber and Crime Busters on Duty! ๐Ÿฆธโ€โ™‚๏ธ๐Ÿ’ผ๐Ÿ”’

These cyber and crime busters are showing that they mean business, keeping the digital and real-world streets safe from sneaky crooks and cyber villains! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ’ป๐Ÿ›ก๏ธ

๐ŸŽฃ Catch of the Day!! ๐ŸŒŠ๐ŸŸ๐Ÿฆž

๐Ÿƒ The Motley Fool: โ€œFool me once, shame on โ€” shame on you. Fool me โ€” you can't get fooled again.โ€ Good olโ€™ George Dubya ๐Ÿ˜‚ Let us tell whoโ€™s not fooling around though; thatโ€™s the Crรผe ๐Ÿ‘€ at Motley Fool. Youโ€™d be a fool (alright, enough already! ๐Ÿ™ˆ) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! ๐Ÿ› Kidding aside, if you check out their website theyโ€™ve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets ๐Ÿค‘ (LINK)

๐Ÿšต Wander: Find your happy place. Cue Happy Gilmore flashback ๐ŸŒ๏ธโ›ณ๐ŸŒˆ๐Ÿ•Š๏ธ Mmmm Happy Placeโ€ฆ ๐Ÿ˜‡ So, weโ€™ve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itโ€™s easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ๐Ÿž๏ธ๐Ÿ˜ (LINK)

๐ŸŒŠ Digital Ocean: If you build it they will come. Nope, weโ€™re not talking about a baseball field for ghosts โšพ๐Ÿ‘ป๐Ÿฟ (Great movie, to be fair ๐Ÿ™ˆ). This is the Digital Ocean whoโ€™ve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youโ€™ll find yourself catching the buzz even if you canโ€™t code (guilty ๐Ÿ˜‘). But if you can and youโ€™re looking for somewhere to test things out or launch something new or simply enhance what youโ€™ve got, weโ€™d recommend checking out their services foโ€™ sho ๐Ÿ˜‰ And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! ๐ŸŒฟ (LINK)

NSO Group: Damn, WhatsApp with that? ๐Ÿ™ƒ

Spyware Showdown: Meta vs. NSO Group! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ’ผ๐Ÿ’ฅ

In a legal showdown straight out of a cyber thriller, a U.S. judge has ruled in favor of Meta, the social media giant, ordering NSO Group, the Israeli spyware heavyweight, to cough up its source code for Pegasus and other sneaky products. ๐Ÿ“ฑ๐Ÿ”๐Ÿ’ป

Victory for Meta! ๐Ÿ†๐Ÿ‘

Meta landed a major win in its legal tussle with NSO Group, which kicked off back in 2019. The lawsuit accused NSO Group of using Meta's platform to dish out its spyware to around 1,400 mobile devices, even targeting two dozen Indian activists and journalists. ๐Ÿ‡ฎ๐Ÿ‡ณ๐Ÿ“ฐ๐Ÿ’”

Zero-Day Shenanigans! ๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ”“๐Ÿ“ž

The attacks were slick, leveraging a zero-day flaw in an instant messaging app to slip Pegasus onto unsuspecting devices with just a missed call. The spyware even wiped away call logs to cover its tracks. ๐Ÿ˜ฑ๐Ÿ“ฒ๐Ÿ•ต๏ธโ€โ™€๏ธ

Spilling the Cyber Beans! ๐Ÿคซ๐Ÿ’ป๐ŸŒ

The judgeโ€™s order demands NSO Group spill the cyber beans on Pegasus, from a year before the attacks to a year after. But, thereโ€™s a twist: NSO Group doesn't have to reveal its clients or spill the beans on server stuff. ๐Ÿค๐Ÿ•ต๏ธโ€โ™‚๏ธ๐Ÿ’ผ

Meta vs. Privacy Police! ๐Ÿ›ก๏ธ๐Ÿ’ฐ๐Ÿ”

While Meta celebrates, it's under the spotlight itself, facing heat from privacy watchdogs in the EU over its "pay or okay" model. Critics say itโ€™s like choosing between privacy or being tracked, raising eyebrows over GDPR rules. ๐Ÿ˜ฌ๐Ÿ’ฐ

Digital Danger Looms! ๐Ÿšจ๐Ÿ”’๐Ÿ’ป

As the cyber saga unfolds, one thing's for sure: the digital world is a wild, wild place, where privacy battles and spyware wars are fought in the shadows, and every click could be a step into the unknown. ๐ŸŒŒ๐Ÿ‘€๐Ÿ•ต๏ธโ€โ™‚๏ธ

๐Ÿ—ž๏ธ Extra, Extra! Read all about it!

Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!

  • ๐Ÿ›ก๏ธ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday ๐Ÿ“…

  • ๐Ÿ’ต Crypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for ๐Ÿ†“

  • ๐Ÿ“ˆ Bitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future ๐Ÿ‘พ

Let us know what you think!

So long and thanks for reading all the phish!

Give us a rating?

Login or Subscribe to participate in polls.