Signal users targeted in backup-stealing phishing attacks
2026-05-30T08:51:57Z•2db16a3443bf5458fdf54cc93f9d5f0d92a33c2e0459b92c1fe11ed41457c005
Adobe-TargetCISA-KEVChrome-RCEClickFix-campaignDeno-RATFox-TempestKali365LinkedIn-phishingMFA-bypassMicrosoft-DefenderShinyHuntersSignalbackup-theftcode-signing-fraudcredential-theftdata-breachexploited-vulnerabilitiesfake-download-sitemalware-distributionphishingsecure-bootsoftware-updatesupply-chain
What happened
A batch of Malwarebytes Labs stories (May 2026) highlights a surge in targeted phishing and credential-theft campaigns, large data breaches, active exploitation of product vulnerabilities, and malicious software distribution. Key items: phishing campaigns impersonating Signal Support to steal backup recovery keys; the Kali365 phishing kit that bypasses MFA to harvest Microsoft/Outlook/Teams/OneDrive credentials; fake ChatGPT/download sites and counterfeit GitHub/SourceForge installers distributing platform-specific malware (including a Deno RAT); the Fox Tempest fake code-signing service that签
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 2db16a3443bf5458fdf54cc93f9d5f0d92a33c2e0459b92c1fe11ed41457c005
- Enrichment time
- 2026-05-30T08:51:57Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.