SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
SOCRadar uncovered a phishing-as-a-service platform that rents out AI voice agents posing as Apple Support to trick stolen-iPhone victims into handing over their Activation Lock passcode.
A malvertising campaign active July 21-22 used Bing ads and a malicious Claude artifact hosted on claude.ai itself to deliver SectopRAT to at least 29 organisations. The staging infrastructure exploited the corporate allow-listing of Anthropic's domain.
North Korea's FAMOUS CHOLLIMA operation has expanded beyond revenue generation into systematic AI intellectual property theft, placing fake engineers inside foundation model developers, GPU cloud providers, and AI safety organisations. CrowdStrike, Microsoft, and the DOJ have documented the mechanism. The AI industry has not caught up.
PhantomSynth is a financially motivated threat actor that has industrialised LLM-generated spear phishing, dramatically reducing the cost of targeted social engineering at scale.