#phishingEmail
Why would you go through all the trouble to put this together and still get so many details blatantly, obviously wrong? I mean… WHAT?!

#phishingScams #phishingEmail #notReal #warning 🚨
May 7, 2024 at 2:43 PM
We return to the topic of phishing with a detailed guide of what to look out for in suspicious emails: remember to think before you click! zurl.co/pRPBK

#cybersecurity #itsecurityoperations #itsecurity #socservices #phishing #phishingemail #guide
Phishing emails: a guide on what to look for
Interfuture Security breaks down all the potentially malicious elements in phishing emails - as one of the most common types of cyber crime, you're going to ...
zurl.co
June 12, 2025 at 2:00 PM
The #phishingemail that fooled your bookkeeper in 2022 looked obviously fake. The one hitting #OrangeCounty #businesses in 2026 doesn't.
AI-generated phishing + deepfake voice fraud are here. 5 controls every #Anaheim & OC SMB needs now 👇
cmitsolutions.com/anaheim-ca-1...
July 8, 2026 at 1:26 PM
This video shares an example of a fake Microsoft Sign-In email scam (phishing email) sent by scammers. Full video on our YouTube channel.

#Phishing #PhishingEmail #PhishingScam #InternetSafetyTips #OnlineSafety #OnlineSafetyAwareness #StaySafeOnline #InfoSec #InformationSecurity #ScamAware101
December 12, 2024 at 1:28 PM
This video shares an example of a fake Netflix email scam (phishing email) sent by scammers to steal your personal information. Full video on our YouTube channel.

#Phishing #PhishingEmail #PhishingScam #ScamAwareness #ScamPrevention #CyberSecurity #CyberSecurityAwareness #ScamAware101
November 14, 2024 at 3:38 PM
This video shares an example of a fake Google Hangouts email scam (phishing email) sent by scammers to steal your personal information. Watch the full video on our YouTube channel. #Phishing #PhishingEmail #ScamPrevention #CyberSecurity #InternetSafety #OnlineSafety #StaySafeOnline #ScamAware101
November 19, 2024 at 6:01 PM
🚨December Update from @ScamAware101🚨

Recent online scams: Amazon Scam, Wrong Number Scam, Fake Order Scam, Brushing Scam / QR Code Scams

Watch video: youtu.be/fN1VNrJB9mg

#Scammer #Phishing #Smishing #OnlineSafety #AmazonScam #PhishingEmail #HappyNewYear #HappyNewYear2025 #ScamAware101
Recent Online Scams (December Update)
YouTube video by ScamAware101
youtu.be
December 31, 2024 at 7:40 PM
ScamAware101 is the FIRST to publish real examples of this NEW phishing email campaign. Fake emails impersonate FedEx and UPS with offer to "Get Your Compensation Now". youtu.be/7GYG8drjvnY

#Phishing #PhishingEmail #Scammers #CyberSecurity #OnlineSafety #InfoSec #InformationSecurity #ScamAware101
Email Scam: Package Delayed or Missing (Fake Compensation Product Scam, FedEx/UPS)
YouTube video by ScamAware101
youtu.be
November 25, 2024 at 5:47 PM
Think you know what a #phishingemail looks like? #scammers aren't just looking for "your bank password.” They are using #GenerativeAI to scrape your social media, clone your boss’s voice, and create pixel-perfect replicas of websites you use.
#HexagonCenter #cybersecurity
youtube.com/shorts/wS9kr...
August 26, 2026 at 6:01 PM
Hackers Abuse OAuth Flaws for Microsoft Malware Delivery #Microsoft #OAuth #Phishingemail
Hackers Abuse OAuth Flaws for Microsoft Malware Delivery
 Microsoft has warned that hackers are weaponizing OAuth error flows to redirect users from trusted Microsoft login pages to malicious sites that deliver malware. The campaigns, observed by Microsoft Defender researchers, primarily target government and public-sector organizations using phishing emails that appear to be legitimate Microsoft notifications or service messages. By abusing how OAuth 2.0 handles authorization errors and redirects, attackers are able to bypass many email and browser phishing protections that normally block suspicious URLs. This turns a standards-compliant identity feature into a powerful tool for malware distribution and account compromise.  The attack begins with threat actors registering malicious OAuth applications in a tenant they control and configuring them with redirect URIs that point to attacker infrastructure. Victims receive phishing links that invoke Microsoft Entra ID authorization endpoints, which visually resemble legitimate sign-in flows, increasing user trust. The attackers craft these URLs with parameters for silent authentication and intentionally invalid scopes, which trigger an OAuth error instead of a normal sign-in. Rather than breaking the flow, this error causes the identity provider to follow the standard and redirect the user to the attacker-controlled redirect URI.  Once redirected, victims may land on advanced phishing pages powered by attacker-in-the-middle frameworks such as EvilProxy, allowing threat actors to harvest valid session cookies and bypass multi-factor authentication. Microsoft notes that the attackers misuse the OAuth “state” parameter to automatically pre-fill the victim’s email address on the phishing page, making it look more authentic and reducing friction for the user. In other cases, the redirect leads to a “/download” path that automatically serves a ZIP archive containing malicious shortcut (LNK) files and HTML smuggling components. These variations show how the same redirection trick can support both credential theft and direct malware delivery.  If a victim opens the malicious LNK file, it launches PowerShell to perform reconnaissance on the compromised host and stage the next phase of the attack. The script extracts components needed for DLL side-loading, where a legitimate executable is abused to load a malicious library. In this campaign, a rogue DLL named crashhandler.dll decrypts and loads the final payload crashlog.dat directly into memory, while a benign-looking binary (stream_monitor.exe) displays a decoy application to distract the user. This technique helps attackers evade traditional antivirus tools and maintain stealthy, in-memory persistence.  Microsoft stresses that these are identity-based threats that exploit intended behaviors in the OAuth specification rather than exploiting a software vulnerability. The company recommends tightening permissions for OAuth applications, enforcing strong identity protections and Conditional Access policies, and applying cross-domain detection that correlates email, identity, and endpoint signals. Organizations should also closely monitor application registrations and unusual OAuth consent flows to spot malicious apps early. As this abuse of standards-compliant error handling is now active in real-world campaigns, defenders must treat OAuth flows themselves as a critical attack surface, not just a background authentication detail.
dlvr.it
March 16, 2026 at 1:58 PM
New KoiLoader Malware Variant Uses LNK Files and PowerShell to Steal Data #CyberSecurity #Data #Phishingemail
New KoiLoader Malware Variant Uses LNK Files and PowerShell to Steal Data
  Cybersecurity experts have uncovered a new version of KoiLoader, a malicious software used to deploy harmful programs and steal sensitive data. The latest version, identified by eSentire’s Threat Response Unit (TRU), is designed to bypass security measures and infect systems without detection. How the Attack Begins The infection starts with a phishing email carrying a ZIP file named `chase_statement_march.zip`. Inside the ZIP folder, there is a shortcut file (.lnk) that appears to be a harmless document. However, when opened, it secretly executes a command that downloads more harmful files onto the system. This trick exploits a known weakness in Windows, allowing the command to remain hidden when viewed in file properties. The Role of PowerShell and Scripts Once the user opens the fake document, it triggers a hidden PowerShell command, which downloads two JScript files named `g1siy9wuiiyxnk.js` and `i7z1x5npc.js`. These scripts work in the background to: - Set up scheduled tasks to run automatically. - Make the malware seem like a system-trusted process. - Download additional harmful files from hacked websites. The second script, `i7z1x5npc.js`, plays a crucial role in keeping the malware active on the system. It collects system information, creates a unique file path for persistence, and downloads PowerShell scripts from compromised websites. These scripts disable security features and load KoiLoader into memory without leaving traces. How KoiLoader Avoids Detection KoiLoader uses various techniques to stay hidden and avoid security tools. It first checks the system’s language settings and stops running if it detects Russian, Belarusian, or Kazakh. It also searches for signs that it is being analyzed, such as virtual machines, sandbox environments, or security research tools. If it detects these, it halts execution to avoid exposure. To remain on the system, KoiLoader: • Exploits a Windows feature to bypass security checks. • Creates scheduled tasks that keep it running. • Uses a unique identifier based on the computer’s hardware to prevent multiple infections on the same device. Once KoiLoader is fully installed, it downloads and executes another script that installs KoiStealer. This malware is designed to steal: 1. Saved passwords 2. System credentials 3. Browser session cookies 4. Other sensitive data stored in applications Command and Control Communication KoiLoader connects to a remote server to receive instructions. It sends encrypted system information and waits for commands. The attacker can: • Run remote commands on the infected system. • Inject malicious programs into trusted processes. • Shut down or restart the system. • Load additional malware. This latest KoiLoader variant showcases sophisticated attack techniques, combining phishing, hidden scripts, and advanced evasion methods. Users should be cautious of unexpected email attachments and keep their security software updated to prevent infection.
dlvr.it
April 4, 2025 at 5:12 AM
I don't think @MrBeast would use a gmail address, let alone an email of t*intslap for promotion. But if Jimmy wants to support @geekazine - I would be for it. #phishingemail
May 20, 2026 at 2:52 PM
🎣 Ever felt like your inbox is a fishing pond full of suspicious bait? Here’s how to spot those slippery phishing emails trying to reel you in.

Are you ready to explore more? Check out the link shared below.

blog.swha.online/how-do-you-i...

#SWHA #PhishingEmail
June 26, 2025 at 6:07 AM
phishingEmail
February 12, 2025 at 5:41 PM
Ein weiteres Phishing-Exemplar, diesmal sind Miles&More (DKB) Kreditkarteninhaber das Ziel.
Nicht klicken!
October 4, 2023 at 5:39 PM
💻 HEADS UP – Not an April Fool’s Day Joke!
Just posted a warning alert on the website 🚨 Be careful—JUNK/SCAM/SPAM emails are circulating from fake Facebook accounts.

Stay cautious out there!

#WebChick #ScamAlert #PhishingEmail #FakeFacebook #CyberSafety #WebsiteUpdate #StaySafeOnline
April 1, 2025 at 2:54 PM