In December 2024, Microsoft Threat Intelligence identified a large-scale malvertising campaign (Storm-0408) that infected nearly one million devices globally, targeting both consumer and enterprise sectors via illegal streaming sites. The sophisticated attack utilized multiple redirection layers and delivered malware through platforms like GitHub, resulting in data theft, including sensitive browser information. Microsoft offers mitigation guidance for organizations.

Phantom Goblin Leveraging Social Engineering Tactics To Deliver Stealer Malware
A sophisticated malware operation named ‘Phantom Goblin’, employing deceptive social engineering techniques, has been identified by Cyble Research and Intelligence Labs (CRIL). The malware uses