We found this fake-invoice campaign while scammers were still building it
2026-06-03T20:51:52Z•34846e9ed6ed30c689a0afc0e3c4de0d9c87587dc3276c199b599055a6ae3d31
credential-theftdata-breachfake-downloadsinfostealermacosmalvertisingmalwaremfa-bypassmobile-malwarephishingphishing-kitsremote-access-trojansocial-engineeringsupply-chain-compromisewindows
What happened
Malwarebytes highlights a wide-ranging surge in social-engineering and malware campaigns: fake invoices and phone-based scams, convincing takedown and copyright notices that steal Google logins, and phishing that targets Signal backups. Attackers increasingly deliver infostealers and RATs via fake downloads, poisoned ads in mobile games, spoofed apps (e.g., BlueWallet), and compromised repositories (GitHub/SourceForge), while phishing kits like Kali365 can bypass MFA to harvest long‑term Microsoft access. Large-scale compromises and data leaks (23andMe, Carnival/ShinyHunters) and supply-chain/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 34846e9ed6ed30c689a0afc0e3c4de0d9c87587dc3276c199b599055a6ae3d31
- Enrichment time
- 2026-06-03T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.