Netskope Threat Labs discovered a large-scale phishing operation involving 260 domains hosting 5,000 malicious PDF files. The files use fake CAPTCHA prompts to lead victims to phishing sites that steal credit card and personal information. Since the start of its activities in late 2024, the campaign has affected over 1,150 organisations and 7,000 users internationally, with a focus on the technology, financial services, and manufacturing sectors. Work is being done to prevent further victims and investigate the threat.

Malware-free attacks surged in 2024 as attackers drop malicious software for legitimate tools
New research reveals that cyber attacks are increasingly using trusted services to carry out malicious activities instead of relying primarily on malware. This shift in