A Link, Click, and a Phish Away! Using Legitimate Domains for a Multi-Step Phishing Attack
![Illustrates the high-level flow a user follows to fall victim to these multi-step phishing campaigns that ultimately attempt to steal credentials.](https://keepaware.com/wp-content/uploads/2024/05/multi-step-phishing-campaign-1024x475.png)
Key points: Overview Keep Aware has observed phishing attacks that use legitimate domains to host links that eventually lead to a credential stealing web page. This article focuses on commonalities between two recent phishing attacks that require a victim to click links on multiple legitimate domains before ultimately landing on a fake login page. This […]
“Looking” for Documents? .. “Look” No Further: A New Trend in Abusing Google Looker Studio for Phishing
![Google Looker Studio is being abused by bad actors to host intermediate phishing webpages.](https://keepaware.com/wp-content/uploads/2024/04/Google-Looker-Studio-image-4-1024x626.png)
Keep Aware has uncovered evidence that Google Looker Studio is being abused by bad actors to host intermediate phishing pages.
Cloudflare R2, Public Buckets and a Phishing Binge: An Analysis of Today’s Threat Landscape
![](https://keepaware.com/wp-content/uploads/2024/03/public-r2-buckets-featured-image-1024x655.png)
Cloudflare public R2 buckets are being abused to host phishing pages.
Clicking Links, From Canva Design to Phishing Site: An Analysis of Today’s Threat Landscape
![Examples of abused Canva designs and of final phishing pages.](https://keepaware.com/wp-content/uploads/2024/02/Screenshot-2024-02-22-at-12.52.40-PM-1024x555.png)
Keep Aware’s Threat Research function shares recent analysis of Canva’s platform abuse for phishing purposes.
The Abuse of Microsoft Dynamics 365 Standalone Forms: An Analysis of Today’s Threat Landscape
![Examples of abused Microsoft Dynamics 365 Customer Insights Journeys standalone forms.](https://keepaware.com/wp-content/uploads/2024/02/Screenshot-2024-02-12-at-10.59.37-AM.png)
An analysis of Microsoft Dynamics 365 standalone forms reveals that, in today’s browsing threat landscape, 1 in 5 forms are threats.
AI and Zero-Day Phishing: Combating The Evolving Browser-Based Security Challenges
![AI and Zero-Day Phishing](https://keepaware.com/wp-content/uploads/2024/02/zero_day_cybersecurity_phishing_email_purses_wallets-1024x512.jpg)
With the rise of generative AI usage across industries, no one should be surprised this trend also applies to the cybercriminal industry. They, too, are integrating AI into their workflows to ultimately increase productivity. This new technological integration into cyber criminals’ and other threat actors’ operations have many IT security professionals left wondering: Before we […]
Understanding Security Support Scams: A Comprehensive Analysis
![Security support scam website impersonating Apple.](https://keepaware.com/wp-content/uploads/2023/11/Screenshot-Apple-Security-Support-Scam.png)
Key Topics and Findings: Overview In today’s interconnected world where practically all employees use the internet, the prevalence of security support scams and other social engineering sites remains a concern. In a threat post specifically about Microsoft security scam websites, our Threat Research team discussed recent web pages impersonating Microsoft that are falsely claiming a […]
From Google Search to Microsoft Security Scam
![Image of a Microsoft security scam site.](https://keepaware.com/wp-content/uploads/2023/11/Screenshot-2023-11-02-at-10.43.19-AM-1024x561.png)
Key Findings: Overview Keep Aware’s Threat Research division identified a recent batch of fraudulent Microsoft support sites. While these scam campaigns are not novel, they persist as an online security risk for all internet users. The scam sites impersonate Microsoft, deceive the user into thinking their machine is infected, and prompt the user to call […]
Browser Notifications Hijacking via DDoS-Protection Mimicry
![Browser Notifications Hijacking Blog](https://keepaware.com/wp-content/uploads/2023/10/Browser-Notifications-Hijacking-1024x536.png)
Key Findings: Overview Keep Aware’s Threat Research team has identified a browser notifications hijacking campaign that impersonates a Russian-based distributed denial of service (DDoS) protection company’s challenge page. This campaign tricks the user into allowing browser notifications and subsequently bombards them with dubious notifications, masquerading as McAfee or Windows Defender alerts, falsely claiming that the […]
Addressing the Risks of Using Prompt-Based AI Tools: A Proactive Strategy
![](https://keepaware.com/wp-content/uploads/2023/09/blog-ai-tool-risk-1024x512.png)
Key Takeaways: Employees are Capitalizing on Prompt-Based AI Tools There has been a trend across industries where businesses are flocking to integrate AI into their technology stack, with the ultimate goal of increasing efficiency and/or efficacy. Alongside this trend, though, employees have been integrating prompt-based AI tools, such as OpenAI’s well-known tool ChatGPT, into their […]