Bad sushi: China-nexus phishers shift to residential proxies

| | Abused, compromised, Spam
Earlier this year, Spamhaus researchers observed a major shift in phishing targeting Japan. Starting in April, a China-nexus threat actor began using residential proxy networks to send phishing emails instead of subnets ...

Spammers Love Mobile Phone IP Space. Here’s How to Fix That.

Mobile phone companies are leaving the door wide open for spammers. They’re hurting their own customers (and the rest of the Internet) - but there’s still time to fix this ...

Sex education in the classroom? Google can help, but there is a compromise!

It’s not uncommon for popular services to eventually fall victim to abuse. In this case, we explore how spammers are using Google Classroom to lure their victims (at elementary school!) to dating ...
There's no such thing as a "free" app!

There’s no such thing as a “free” app!

Downloading a free application and installing it on an internet-connected device can lead to you not being able to send email. This is because some apps allow third parties to access your ...

Let’s talk about the danger of residential proxy networks

In our experience, residential proxies are an often overlooked security threat; one that can be very difficult to remediate for the end user who -in our experience- is entirely unaware of its ...
The holiday hack – a reminder of why you shouldn’t always trust emails

The holiday hack – a reminder of why you shouldn’t always trust emails

Here’s a cautionary tale to anyone and everyone who uses email. The learning is simple: Always be vigilant, especially if its content asks you to provide personal information or click on links ...

When doorbells go rogue!

Here's a story of doorbells, specific software development kits (SDKs), proxies, and miscreants using your home network to send spam ...

Using OMI on Microsoft Azure? Here’s an update you need to read

An easy-to-exploit security vulnerability that allows remote code execution (RCE) on virtual machines where Open Management Infrastructure (OMI) is installed has been observed. Users need to take action ...
Wordpress compromises: What's beyond the URL?

WordPress compromises: What’s beyond the URL?

One of the many tricks in the modern cybercriminal miscreant's toolbox is using compromised websites to evade spam filters and domain reputation systems. Whether hiding a web-based exploit or just getting a ...

Emotet is disrupted, but the malware it installed lives on

The successful takedown of the Emotet C2 infrastructure announced January 27th 2021 is no small accomplishment, both from a technical point of view and for the larger safety and security of the ...