Citadel, Two Sigma, Point72 and Millennium were targeted in a coordinated voice phishing campaign. No malware. No zero-day. Attackers called employees and asked for access.
Read the full breakdown π
π‘οΈ Security Awareness for the age of AI β β¨ AI-driven vishing, smishing, and phishing β π arsen.co
- π₯ This week in the news: - @binance's CSO: employees who repeatedly fail phishing tests will be fired! - @CrowdStrike flags surge in vishing - @okta shares a full BTS of a vishing operation - @ChatGPT joins the top 10 most impersonated brands in phishing
- ClickFix and vishing attacks are evolving fast, making social engineering an ever growing threat. See the latest campaigns uncovered by @msftsecurity, @GroupIB & @kaspersky; and how @arsen helps train your team. π
- π¨ @okta details a vishing campaign where @Microsoft365 users are tricked into enrolling attacker-controlled Entra passkeys. Time to test these workflows with company-scale vishing simulations. π
- π‘ClickFix is a type of social engineering attack that makes people run malware on their own without the attacker needing to use an exploit. Learn more: arsen.co/en/resources/cβ¦We are tracking a MaaS #ClickFix operation using Polygon #blockchain as a resilient C2 config store. So far, 130+ compromised sites with 15 rotating C2s. Victim telemetry is periodically exfiltrated and stage 3 execution drops an infostealer. Details at bit.ly/4fmKZ8g


