Signal users targeted in backup-stealing phishing attacks
2026-05-31T08:52:08Z•7b4cca799cd54bfcde6c56b7700eb62e20084616305364ffecd03e22bd0f1a22
RATad-abusebackup-theftbrowser-vulnerabilitiescertificate-rotationclickfixcms-exploitcode-signing-fraudcredential-theftdata-breachdeno-ratexploited-vulnerabilitiesfake-softwaremalware-distributionmfa-bypasspersonal-data-exposurephishingsoftware-repo-abusesupply-chainweb-compromise
What happened
Malwarebytes Labs headlines covering a wide range of active threats and security issues: phishing campaigns targeting Signal users to steal backup recovery keys; a Carnival breach affecting nearly 6 million records and other large data exposures (NYC Health + Hospitals); warnings about Windows Secure Boot certificate replacements; a fake ChatGPT download site delivering Windows and macOS malware; Kali365 phishing kit that bypasses MFA to steal Microsoft/Office365 logins; fake LinkedIn phishing using Adobe Target to track and redirect victims; fake installers on GitHub/SourceForge distributingD
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 7b4cca799cd54bfcde6c56b7700eb62e20084616305364ffecd03e22bd0f1a22
- Enrichment time
- 2026-05-31T08:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.