Phishers hide scam links with IPv6 trick in “free toothbrush” emails

2026-03-11T20:51:55Z3d9d78ede6b34501f078e4c1296f4140cc1332ec108d6099af49e2655f048f5a
account-takeoverandroidbrowser-notificationscredential-theftfake-installersfake-updatesfbi-wiretapgithub-maliciousinfostealeripv6-trickoauth-abusepatch-tuesdayphishingqualcommrobocallssextortionshub-stealersignalsupply-chaintargeted-attackswhatsappzero-day

What happened

A batch of Malwarebytes reports highlights multiple active scams and malware campaigns plus notable vulnerability fixes in March 2026. Phishers used an IPv6 trick to hide scam links (United Healthcare/free toothbrush lure); sextortion emails reused real passwords harvested from disposable inboxes; tax-season robocalls and quiz sites abusing browser notifications for follow-on fraud were observed. Attackers abused OAuth redirects to funnel victims from legitimate Google/Microsoft pages to phishing/malware, and campaigns tricked users into sharing verification codes to hijack Signal and WhatsApp

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
3d9d78ede6b34501f078e4c1296f4140cc1332ec108d6099af49e2655f048f5a
Enrichment time
2026-03-11T20:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.