ThreatInsight
@threatinsight
Proofpoint's insights on targeted attacks and the cybersecurity threat landscape.
The site also features a “Customer Service” chat box. If a user messages, a threat actor responds and walks through the steps to install ScreenConnect. Based on the chats we've examined, a real person (not AI) is likely operating the chat to instruct users on malware installation.
Emails impersonate COLDCARD and purport to highlight a security audit relating to the incident. Messages contain a URL that leads to a site impersonating COLDCARD with a “Start Hardware Audit” button.
A COLDCARD hardware wallet vulnerability is being exploited by threat actors. The reported firmware flaw has led to tens of millions worth of Bitcoin stolen. We've observed social engineering with “hardware audit” themes impersonating #COLDCARD in email-based phishing campaigns.
Our Proofpoint AI threat researchers continue to observe activity on underground criminal forums, suggesting that Indirect Prompt Injection (IDPI) could soon be leveraged as an intrusion vector. Explore the methods that are being actively developed and sold: www.proofpoint.com/us/blog/thre....
Our researchers discovered that a Russia-aligned threat actor was exploiting a previously unknown (zero-day) vulnerability against Zimbra mailservers. We alerted government partners, with whom we have collaborated on further discovery. Blog: www.proofpoint.com/us/blog/thre...
The StealC ecosytem #OperationEndgame led to the seizure of more than 25.6M unique creds stolen from +385k compromised sites. Proofpoint was proud to contribute to the operation alongside industry partners. Listen to Discarded for a scoop inside the disruption. www.proofpoint.com/us/podcasts/...
• Targeting is opportunistic, but campaigns aimed at Finserv, healthcare, and government entities were more frequent. • It's always executed via DLL side-loading. Purpose: ensure the target system isn’t a sandbox or malware analyst’s VM before dropping and executing the payload.
Researchers at Proofpoint are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. The self-proclaimed “underground's most lethal crypter” has been observed delivering a wide range of RATs and infostealers. Blog: www.proofpoint.com/us/blog/thre...
Back by popular demand, senior threat researcher Joe Wise will join our next Intercepted livestream on July 22nd. Joe will share real examples of active threat campaigns, malware samples, tips, tricks, and more research for defenders. Register to join us 👉 www.proofpoint.com/uk/resources...
The campaign featured two one-month clusters of spraying activity against roughly 80,000 user accounts across nearly 3,000 tenants.
Since May 2026, we’ve seen UNK_MassTraction target physics and engineering departments by chaining Roundcube vulns to: • Execute JavaScript via XSS • Steal browser-stored credentials • Gain mail server access • Deploy either a webshell or an in-memory VShell backdoor
🚨 New research: Proofpoint has identified a suspected China-aligned espionage cluster, UNK_MassTraction, exploiting multiple Roundcube n-day vulnerabilities to compromise mail servers at U.S. and Canadian universities. Analysis, infection chain & IOCs: www.proofpoint.com/us/blog/thre....
In April 2026, Proofpoint’s cloud telemetry captured a shift in the ISPs from which NovaCookies activity originated, a pattern is consistent with established tradecraft of migrating hosting or proxy services to evade detection.
Proofpoint observed an intermittent burst in Sneaky2FA activity until February 2026, when researchers first identified the NovaCookies variant. Malicious activity intensified from March to May as this new variant was adopted, but declined in June.
Researchers from Proofpoint have reported an increase in AitM activity originating from #NovaCookies, a suspected variant of the #Sneaky2FA phishing kit.
FIFA FANS ‼️ Cybercriminals are using #FIFAWorldCup excitement to steal your personal info and credit card details. One recent email scam we observed used the subject line: “Congratulations! You're Eligible for the FIFA World Cup 2026 Giveaway” 🧵 1/5
Just announced by @europol.europa.eu: the global #OperationEndgame initiative has disrupted the #StealC ecosystem, a prominent information-stealing malware operation. See our blog for details: www.proofpoint.com/us/blog/thre...
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame. ❌ 100 servers and domains worldwide dismantled ❌ 14,971 websites remediated Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
Emails contained a URL that led to counterfeit authentication pages designed to harvest user credentials.
The campaigns impersonated two financial firms, CommSec and FSM One, to target people in #Australia and #Singapore. The messages purported to invite people to apply for eligibility to purchase SpaceX stock.
Over six weeks, we observed the actor targeting nearly 100 organizations across technology, #cryptocurrency, finance, and education sectors. Targets were lured through fake recruiter outreach, code review requests, and developer collaboration opportunities.
We consider it one of the most unique actors we track due to its high volume and wide variety of lure themes, targeting, and objectives. In our blog, we share recent campaigns observed by TA4922 that illustrate typical behaviors.
Sarah Sabotka, staff threat researcher at Proofpoint, is speaking at #Layer8Conference — the only event dedicated to #OSINT and #socialengineering threats facing businesses today. If you're a security leader, you won't want to miss it! June 5–6 | Boston, MA Event info: layer8conference.com
Like EvilTokens, most of the activity we see is using “vibe coded” techniques. It's unclear whether most are copying & modifying publicly known tools or using similar prompts to generate nearly identical attack flows wholesale. Here's an EvilTokens landing page from March 2026.
Device code phishing is exploding across the threat landscape, with new device code phishing tools emerging every week. Our new blog explores why adoption of this technique has surged over the past year. www.proofpoint.com/us/blog/thre... A few key points below. 🧵⤵️
ODx’s device code capabilities are using Kali365, a device code PhaaS. Kali365 is just one of many such kits available for purchase. It’s unclear whether ODx stole or purchased Kali365, or partnered with them to integrate directly into their service.
In the observed campaign, the actor used compromised senders to deliver URLs leading to the ODx device code phishing landing page. The landing pages included multiple different themes including impersonating SharePoint, Adobe, and Docusign.
Our award-winning threat research podcast series, Discarded, is celebrating 100 episodes this week! 🎉 Stream now for a trip down memory lane, a few laughs, and a look ahead to what's next in cybersecurity. Cheers to 100 episodes! 🍾 www.proofpoint.com/us/podcasts/...
Proofpoint baited a cargo/transport industry threat actor into performing its malicious activities in a decoy environment operated by Deception.Pro for 30+ days. What resulted: rare, extended visibility into post-compromise operations, tooling, & decision-making. www.proofpoint.com/us/blog/thre...
Our new Discarded podcast episode explores the stealthy world of backdoors, malware detection, and the “secret signals” threat actors use to stay hidden. Stream now for expert insights on signature development, PCAP analysis, and countering espionage tools. 🎙️ www.proofpoint.com/us/podcasts/...