We found this fake-invoice campaign while scammers were still building it
2026-06-04T08:51:52Z•ec2b1c7cca0f76ce7f501083f3bdba6d1e10e7e5478f6f1a7d2820ab4e2016e1
23andMeCarnivalClickFix campaignDeno RATGhost CMSKali365MFA bypassWindows malwaread fraud/abusecredential theftdata breachfake downloadsfake invoicesfake takedown noticesinfostealermacOS malwarephishingphone scamssecure bootsignal phishingsocial engineeringsupply chain/hosting abuse
What happened
A set of Malwarebytes posts from late May–early June 2026 describing multiple active social‑engineering and malware campaigns. Key themes: a fake‑invoice/phone‑scam campaign that pressures victims into payment or device surrender; an increase in infostealer usage as phishing payloads; phishing kits that bypass MFA (e.g., Kali365); targeted credential theft (Signal backup‑key phishing, fake LinkedIn emails abusing Adobe Target); fake downloads serving platform‑specific malware (macOS BlueWallet impostor, fake ChatGPT site, fake software on GitHub/SourceForge distributing Deno RAT); large-scale,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- ec2b1c7cca0f76ce7f501083f3bdba6d1e10e7e5478f6f1a7d2820ab4e2016e1
- Enrichment time
- 2026-06-04T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.