We found this fake-invoice campaign while scammers were still building it

2026-06-03T20:51:52Z34846e9ed6ed30c689a0afc0e3c4de0d9c87587dc3276c199b599055a6ae3d31
credential-theftdata-breachfake-downloadsinfostealermacosmalvertisingmalwaremfa-bypassmobile-malwarephishingphishing-kitsremote-access-trojansocial-engineeringsupply-chain-compromisewindows

What happened

Malwarebytes highlights a wide-ranging surge in social-engineering and malware campaigns: fake invoices and phone-based scams, convincing takedown and copyright notices that steal Google logins, and phishing that targets Signal backups. Attackers increasingly deliver infostealers and RATs via fake downloads, poisoned ads in mobile games, spoofed apps (e.g., BlueWallet), and compromised repositories (GitHub/SourceForge), while phishing kits like Kali365 can bypass MFA to harvest long‑term Microsoft access. Large-scale compromises and data leaks (23andMe, Carnival/ShinyHunters) and supply-chain/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
34846e9ed6ed30c689a0afc0e3c4de0d9c87587dc3276c199b599055a6ae3d31
Enrichment time
2026-06-03T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.