From Russia with love

A few months ago I was informed of an investigation into a type of fraud that sees some infrastructure based in Russia at the center of attention. I was contacted because Matrix had reported a domain that was later used for fraud. This is the report: https://urlscan.io/result/37dd713d-0cfe-4fd4-a377-1f154ecd2f4f/ This is the full article on Qurium: https://www.qurium.org/alerts/deep-fake-video-of-maria-ressa-connected-to-cyberscam-network-in-russiaContinue reading From Russia with love

Phishing attack against Facebook users

This morning Matrix located a file containing Facebook user credentials stolen using a phishing attack. The malicious site is "ab-portalwiedza.xyz". 16 hours after the report of the attack, the site is still online even if the file containing the credentials is no longer visible, I imagine because the criminal changed its name. The site presents … Continue reading Phishing attack against Facebook users

Intesa San Paolo phishing kit

A few hours ago Matrix identified a phishing kit targeting customers of the Italian bank Intesa San Paolo (intesasanpaolo[.]com). This site is hosted on cprapid[.]com, the full url is weblntesasanpaolo[.]35-180-129-166[.]cprapid[.]com. I just report it as malicious on urlscan.io. The kit code is a mess 😦 I don't think the low quality indicates attempts at evasion, … Continue reading Intesa San Paolo phishing kit

Attack against Zoom

Today I'll tell you about an attack detected a few hours ago by Matrix and reported on urlscan.io. This is a fairly complex attack against Zoom. The attackers registered on Namecheap a domain (us06webzoomus[.]pro) reminiscent of Zoom subdomains and deployed a series of files. Here we find three malware (Android and Windows), static content (scripts, … Continue reading Attack against Zoom