Signal users targeted in backup-stealing phishing attacks

2026-05-31T20:51:54Z26b7bd70cc3576ac483ba774942b4e620d916cf76fc39c5201668f6b9159dbfd
Adobe Target abuseCarnivalChromeClickFixDeno RATFirefoxFox TempestKali365MFA bypassMicrosoft Defender exploitationNYC Health + HospitalsShinyHuntersSignalbackup key theftbrowser vulnerabilitiescredential theftdata breachfake downloadsghost-cmsmalwaremalware signing abusephishingsocial engineeringsupply chain abuse

What happened

A batch of Malwarebytes posts (May 2026) highlights a surge in credential- and backup-stealing phishing, large data breaches, active exploitation of endpoint/browser flaws, and widespread malware distribution via fake downloads and compromised sites. Notable incidents include Signal-targeted phishing to steal backup recovery keys, the Kali365 phishing kit that bypasses MFA to persist in Microsoft accounts, fake ChatGPT/GitHub/SourceForge downloads distributing Deno RAT, a massive ClickFix campaign abusing a Ghost CMS flaw, abuse of Adobe Target in LinkedIn credential phishing, and the dismantl

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
26b7bd70cc3576ac483ba774942b4e620d916cf76fc39c5201668f6b9159dbfd
Enrichment time
2026-05-31T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.