Signal users targeted in backup-stealing phishing attacks

2026-05-30T08:51:57Z2db16a3443bf5458fdf54cc93f9d5f0d92a33c2e0459b92c1fe11ed41457c005
Adobe-TargetCISA-KEVChrome-RCEClickFix-campaignDeno-RATFox-TempestKali365LinkedIn-phishingMFA-bypassMicrosoft-DefenderShinyHuntersSignalbackup-theftcode-signing-fraudcredential-theftdata-breachexploited-vulnerabilitiesfake-download-sitemalware-distributionphishingsecure-bootsoftware-updatesupply-chain

What happened

A batch of Malwarebytes Labs stories (May 2026) highlights a surge in targeted phishing and credential-theft campaigns, large data breaches, active exploitation of product vulnerabilities, and malicious software distribution. Key items: phishing campaigns impersonating Signal Support to steal backup recovery keys; the Kali365 phishing kit that bypasses MFA to harvest Microsoft/Outlook/Teams/OneDrive credentials; fake ChatGPT/download sites and counterfeit GitHub/SourceForge installers distributing platform-specific malware (including a Deno RAT); the Fox Tempest fake code-signing service that签

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
2db16a3443bf5458fdf54cc93f9d5f0d92a33c2e0459b92c1fe11ed41457c005
Enrichment time
2026-05-30T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.