Signal users targeted in backup-stealing phishing attacks
2026-05-31T20:51:54Z•26b7bd70cc3576ac483ba774942b4e620d916cf76fc39c5201668f6b9159dbfd
Adobe Target abuseCarnivalChromeClickFixDeno RATFirefoxFox TempestKali365MFA bypassMicrosoft Defender exploitationNYC Health + HospitalsShinyHuntersSignalbackup key theftbrowser vulnerabilitiescredential theftdata breachfake downloadsghost-cmsmalwaremalware signing abusephishingsocial engineeringsupply chain abuse
What happened
A batch of Malwarebytes posts (May 2026) highlights a surge in credential- and backup-stealing phishing, large data breaches, active exploitation of endpoint/browser flaws, and widespread malware distribution via fake downloads and compromised sites. Notable incidents include Signal-targeted phishing to steal backup recovery keys, the Kali365 phishing kit that bypasses MFA to persist in Microsoft accounts, fake ChatGPT/GitHub/SourceForge downloads distributing Deno RAT, a massive ClickFix campaign abusing a Ghost CMS flaw, abuse of Adobe Target in LinkedIn credential phishing, and the dismantl
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 26b7bd70cc3576ac483ba774942b4e620d916cf76fc39c5201668f6b9159dbfd
- Enrichment time
- 2026-05-31T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.