Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Netcraft

@Netcraft@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Netcraft provides powerful phishing detection, cybercrime disruption, and website takedown solutions to the world's largest organizations.

11 Followers
18 Following
17 Posts
Joined August 19, 2025
Netcraft.com:
Netcraft.com
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

RE: https://infosec.exchange/@BleepingComputer/116811341383412305

New breaking research from us 👇

And you can read more here https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat

Infosec Exchange

BleepingComputer (@BleepingComputer@infosec.exchange)

The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. https://www.bleepingcomputer.com/news/security/bluekit-phishing-kit-adopts-browser-in-the-middle-for-login-theft/

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

Observed in the wild: A phishing page that requests getUserMedia() permissions under the guise of a Visa Secure payment check, then silently captures frames from the front-facing camera every 2 seconds and POSTs them to a Telegram bot via hardcoded bot token in client-side JS.

A second variant records 20 stills + 10 short video clips before exfil. The Telegram credentials are exposed in the page source — an operational weakness that creates a disruption opportunity.

Full code-level analysis by Ivan Khamenka:

https://www.netcraft.com/blog/how-camera-first-phishing-turns-payment-verification-into-surveillance

#infosec #phishing #threatintel #javascript

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data
netcraft.com

Camera-First Phishing: How Fraudsters Use Browser Permissions to Harvest Identity Data

A newly observed phishing campaign impersonates payment verification to harvest selfies, videos, location data, and device information. Learn how camera-first phishing turns browser permissions into a powerful collection channel.

1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

EvilTokens abuses OAuth device code flow to phish credentials without ever rendering a fake login page.

The victim authenticates through a legitimate Microsoft prompt. The attacker gets the token. No credential harvest, no spoofed UI — just a device code the victim was socially engineered into approving.

Netcraft's analysis covers the full attack chain including GhostPairing, a variant that pairs attacker-controlled devices mid-session.

Detailed breakdown with campaign infrastructure observations: https://www.netcraft.com/blog/eviltokens-and-oauth-abuse

#infosec #phishing #OAuth #threatintel

EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
netcraft.com

EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA

Netcraft uncovers how EvilTokens enables large-scale OAuth device code phishing campaigns, abuses Microsoft authentication flows, and powers emerging attacks like GhostPairing.

1
0
2
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

🚨 NEW THREAT INTEL REPORT: A football sponsorship isn’t always what it seems. ⚽
Our latest research uncovers how Felix Markets used sports to launder legitimacy for a fraudulent investment platform.

https://www.netcraft.com/blog/fake-investment-platform-reputation-laundering-felix-markets

#ReputationLaundering #BrandProtection #ScamAlert

Fake Investment Platform Reputation Laundering: Felix Markets
netcraft.com

Fake Investment Platform Reputation Laundering: Felix Markets

Learn how Felix Markets posed as a regulated forex broker, exploited fake authorities, copied legal documents, and used sports sponsorship to appear legitimate.

1
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 11mo ago

📞 “Hello, this is your bank…”

No it’s not.

Learn how PNC’s team spots these calls before they reach customers.
💡 Webinar Nov 17 – Reserve your spot:

https://www.netcraft.com/lp/disrupt-phone-fraud-webinar

#Fraud #Cybersecurity #BrandProtection

netcraft.com
1
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
Browser-in-the-Middle phishing has evolved. Bluekit uses a session replay library (rrweb) to stream a live, interactive login page from the attacker's browser to the victim's. It looks and behaves exactly like the real thing — because it is. New research from our team: https://www.netcraft.com/blog/bluekit-phishing-as-a-service-threat #phishing #PhishingKits
Bluekit Phishing-as-a-Service: Browser-in-the-Middle (BitM) Analysis
netcraft.com

Bluekit Phishing-as-a-Service: Browser-in-the-Middle (BitM) Analysis

Netcraft analyzes Bluekit, a Browser-in-the-Middle phishing kit that streams legitimate login pages to victims using rrweb. Learn how it works, why it differs from Evilginx, and the detection opportunities for defenders.

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
How financial institutions should be preparing for the upcoming new #Scams Prevention Framework in #Australia https://www.netcraft.com/blog/australia-scams-prevention-framework-what-the-new-obligations-mean-for-banks
Australia's Scams Prevention Framework: What Banks Must Do Before March 2027
netcraft.com

Australia's Scams Prevention Framework: What Banks Must Do Before March 2027

Australia's Scams Prevention Framework is now law, with sector designations confirmed and codes in final consultation. Here's what banks need to do before the March 2027 deadline.

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago

Brand impersonation is being used at scale for casino affiliate fraud.

Ads on #Meta/#TikTok claim a well-known brand "launched" a slots product. The landing page mimics an app store listing. Tapping "Install" registers a Progressive Web App that opens a casino endpoint through an affiliate link, title bar still showing the impersonated brand's name/icon.

We've observed this across UK financial brands, retail (Tesco, Amazon), and streaming (Netflix), plus DE/ES-language variants.

IOCs, domain patterns, and affiliate CPA figures ($50–$350/depositing player) in the full post: https://www.netcraft.com/blog/branded-gambling-campaigns-how-scammers-are-exploiting-trusted-brands

Branded Gambling Campaigns: How Scammers Exploit Trusted Brands
netcraft.com

Branded Gambling Campaigns: How Scammers Exploit Trusted Brands

Learn how scammers use fake gambling ads, app store pages, and PWAs to impersonate trusted brands and drive users to online casinos.

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

RE: https://infosec.exchange/@BleepingComputer/115663627288221100

Proud to support NCSC’s proactive notifications pilot. External scanning helps surface exposed services and known vulnerabilities so organizations can remediate faster. Important initiative outlined here.

Infosec Exchange

BleepingComputer (@BleepingComputer@infosec.exchange)

The UK's National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. https://www.bleepingcomputer.com/news/security/ncscs-proactive-notifications-warns-orgs-of-flaws-in-exposed-devices/

0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 10mo ago

Attackers are leveraging behavioral science to shape their campaigns.
Netcraft expects this to intensify in 2026, making intent detection just as important as artifact detection.

https://vmblog.com/archive/2025/11/19/five-cybersecurity-predictions-for-the-year-ahead.aspx

#BrandProtection #ThreatIntelligence #Phishing #Infosec

Five Cybersecurity Predictions for the Year Ahead - VMblog
VMblog

Five Cybersecurity Predictions for the Year Ahead - VMblog

    Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive. By Andrew Brandt, principal threat researcher; Gina Chow, emerging threat specialist; and Ginny Spicer, threat analyst, NetcraftEvery new year creates an opportunity to look at what's come before and plan for what's…

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 11mo ago

Google has filed suit against a Chinese-based phishing-kit platform behind toll-road & delivery scams. Meanwhile our team at Netcraft uncovered 17,500+ domains targeting 316 global brands.

Read how PhaaS is going industrial: https://www.netcraft.com/blog/inside-the-lighthouse-and-lucid-phaas-campaigns-targeting-316-global-brands

Lighthouse & Lucid: Netcraft Exposes 17,500+ Phishing-as-a-Service Domains
netcraft.com

Lighthouse & Lucid: Netcraft Exposes 17,500+ Phishing-as-a-Service Domains

Netcraft uncovers 17,500+ phishing domains linked to the Lighthouse and Lucid PhaaS platforms, targeting 316 brands across 74 countries. Learn how automation and intelligence help disrupt these evolving threats.

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 13mo ago

🚨NEW RESEARCH🚨

Attackers don’t always need zero-days. Sometimes, all it takes is a single character.
Our researchers recently uncovered a phishing wave abusing the Japanese Hiragana character “ん” – a lookalike that resembles a forward slash or Latin “n.” By inserting it into domain names, attackers are creating URLs that appear legitimate at a glance but redirect victims to credential harvesters, fake crypto wallets, and malware downloads.

Our investigation traced more than 600 malicious domains leveraging this technique.

Why it matters:
Unicode confusion lets these domains slip past regex filters and automated scanners. Punycode encoding makes them DNS-valid and browser-friendly.

The tactic spreads fast, beyond crypto into travel, enterprise, and education. This is a textbook example of attackers weaponizing subtlety.

👉 Read our full analysis here: https://www.netcraft.com/blog/down-the-hiragana-hole-uncovering-a-new-wave-of-lookalike-domains

#BrandProtection #Cybersecurity #ThreatIntelligence

netcraft.com
0
0
1
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3mo ago
Fragmented brand protection monitoring creates blind spots: threat actors reuse domains, hosting, phone numbers, and accounts across channels, so takedowns on one surface don't stop the campaign elsewhere. Our new post covers why channel-centric monitoring breaks containment and what cross-channel correlation looks like in practice. https://www.netcraft.com/blog/brand-protection-monitoring
Brand Protection Monitoring Struggles as Attack Surfaces Sprawl
netcraft.com

Brand Protection Monitoring Struggles as Attack Surfaces Sprawl

Brand protection breaks down when monitoring is fragmented. Learn how attack surface sprawl creates risk, and why cross-channel coverage is essential.

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Kelly Bissell (former CVP, Fraud & Abuse, Microsoft) pushes back on headline-driven threat prioritization: nation-state attribution generates press coverage, but fraud is what actually costs organizations money. Full discussion in IWG Rewind, our on-demand series of exclusive talks. #Fraud #InfoSec #CISO
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Netcraft's Luke Wood examines how AI-assisted #VibeCoding platforms are being abused to build phishing infrastructure. Inconsistent KYC checks, easily bypassed content filters, and free-tier abuse are enabling low-skill threat actors to generate functional credential-harvesting pages with no development experience. One tracked platform's abuse reports grew from <250/month (Jan 2025) to 4,000+/month (Oct 2025). netcraft.com/blog/rise-of-ai-vibe-coding-and-new-cyber-threats
0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 2mo ago
Our recent research tested 2,905 AI-generated responses to natural-language queries about brand login pages across #ChatGPT, #Copilot, #Gemini, and #perplexity 1.7% of responses contained malicious links; of the 20,706 total links returned, 0.28% pointed to attacker-controlled infrastructure rather than parked or hallucinated domains. This marks a shift from 2025 findings, where the primary risk was #AI citing unclaimed domains. Full methodology and case examples (including a Wells Fargo phishing page served via Copilot) here: https://www.netcraft.com/blog/threat-actors-are-finding-their-way-into-your-ai-summaries
Malicious links in AI summaries and search results
netcraft.com

Malicious links in AI summaries and search results

As answer engines become more ubiquitous in the average user’s web experience and more integrated into their browsing behavior, incorrect and malicious results become more dangerous.

0
0
0
0
Open post
Netcraft @Netcraft@infosec.exchange
· 3w ago
New analysis: In 2026, 64% of Netcraft takedowns and disruptions relied on proprietary intelligence that open-source monitoring would not have surfaced on its own — cybercrime reporting networks, internet telemetry, proxy infrastructure reaching geofenced/cloaked content, and historical classification data. The underlying problem is that OSINT sources (DNS records, CT logs, public threat feeds) are, by definition, visible to everyone — including the threat actors. More than 95% of phishing victim traffic occurs within 20 hours of detection, so detection speed measured in days rather than minutes represents a materially different outcome, not a slower version of the same one. We've got a breakdown of the visibility gap, evidence requirements for takedown, and the questions worth asking any DRP vendor on our blog: https://www.netcraft.com/blog/attackers-dont-publish-an-asset-inventory #infosec #threatintel #phishing
Netcraft: Attackers don
netcraft.com

Netcraft: Attackers don

Why public threat feeds aren

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Pricing
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:25:18 UTC