We found this fake-invoice campaign while scammers were still building it

2026-06-04T08:51:52Zec2b1c7cca0f76ce7f501083f3bdba6d1e10e7e5478f6f1a7d2820ab4e2016e1
23andMeCarnivalClickFix campaignDeno RATGhost CMSKali365MFA bypassWindows malwaread fraud/abusecredential theftdata breachfake downloadsfake invoicesfake takedown noticesinfostealermacOS malwarephishingphone scamssecure bootsignal phishingsocial engineeringsupply chain/hosting abuse

What happened

A set of Malwarebytes posts from late May–early June 2026 describing multiple active social‑engineering and malware campaigns. Key themes: a fake‑invoice/phone‑scam campaign that pressures victims into payment or device surrender; an increase in infostealer usage as phishing payloads; phishing kits that bypass MFA (e.g., Kali365); targeted credential theft (Signal backup‑key phishing, fake LinkedIn emails abusing Adobe Target); fake downloads serving platform‑specific malware (macOS BlueWallet impostor, fake ChatGPT site, fake software on GitHub/SourceForge distributing Deno RAT); large-scale,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
ec2b1c7cca0f76ce7f501083f3bdba6d1e10e7e5478f6f1a7d2820ab4e2016e1
Enrichment time
2026-06-04T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · We found this fake-invoice campaign while scammers were still building it · Baitaphish