Signal users targeted in backup-stealing phishing attacks

2026-05-31T08:52:08Z7b4cca799cd54bfcde6c56b7700eb62e20084616305364ffecd03e22bd0f1a22
RATad-abusebackup-theftbrowser-vulnerabilitiescertificate-rotationclickfixcms-exploitcode-signing-fraudcredential-theftdata-breachdeno-ratexploited-vulnerabilitiesfake-softwaremalware-distributionmfa-bypasspersonal-data-exposurephishingsoftware-repo-abusesupply-chainweb-compromise

What happened

Malwarebytes Labs headlines covering a wide range of active threats and security issues: phishing campaigns targeting Signal users to steal backup recovery keys; a Carnival breach affecting nearly 6 million records and other large data exposures (NYC Health + Hospitals); warnings about Windows Secure Boot certificate replacements; a fake ChatGPT download site delivering Windows and macOS malware; Kali365 phishing kit that bypasses MFA to steal Microsoft/Office365 logins; fake LinkedIn phishing using Adobe Target to track and redirect victims; fake installers on GitHub/SourceForge distributingD

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
7b4cca799cd54bfcde6c56b7700eb62e20084616305364ffecd03e22bd0f1a22
Enrichment time
2026-05-31T08:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.