Hackers and scammers are increasingly targeting user credentials, according to research by Cofense. Indicators of credential phishing spiked by nearly 45% in Q3 2021 relative to the previous quarter, and by 85% compared to Q3 2022. Cyber criminals are exploiting Google AMP and QR codes to make their phishing links appear more legitimate. The most common malware associated with phishing during the quarter was Agent Tesla keylogger and FormBook. .com and .ru were the domains most frequently used by scammers.

MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control – SC Media
MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control SC Media

