hacker-news · Crawled Sep 4, 2026

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

6 IoCs 1 Actors 1 Malware
Read original article ↗

AI Summary

Multiple threat campaigns are leveraging social engineering, phishing-as-a-service (PhaaS), and abuse of trusted software to gain unauthorized access to corporate and personal accounts. Microsoft Teams is being abused in vishing attacks to trick users into granting remote access via RMM tools, while PhaaS platforms like Outsider and BlueKit enable credential theft through browser-in-the-middle attacks. Malicious actors are also exploiting misconfigurations in AI instruction files (llms.txt) to deliver malicious packages, and trojanized Electron apps are distributing the RevStealer information stealer. Additionally, attackers are abusing legitimate tools like Faronics Deploy and ScreenConnect to establish persistent remote access, and ransomware operations such as The Gentlemen and CRPx0 continue to target organizations with sophisticated, multi-stage attack chains.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 6 extracted

Type Value Detail
Domain crpx0[.]su Details →
Domain www[.]mxsetuplogi[.]com Details →
Filename llms.txt Details →
Filename llms-full.txt Details →
Package clerk-next-fix-auth-protection Details →
Package @clerk/eslint-plugin Details →

MITRE ATT&CK TTPs 15 techniques