<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Fraud on CuraSec</title><link>https://curasec.metacog.co.kr/tags/fraud/</link><description>Recent content in Fraud on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/fraud/index.xml" rel="self" type="application/rss+xml"/><item><title>INTERPOL Operation Jackal IV Arrests 58 in Global Cyber Fraud Sweep</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-interpol-operation-jackal-iv-arrests-58-identifies-263-in-gl/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-interpol-operation-jackal-iv-arrests-58-identifies-263-in-gl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Operation Jackal IV provides updated context on West African cybercrime network scale and reach; no IOCs or TTPs published, so no immediate detection work, but useful for understanding threat actor landscape if your sector is targeted by BEC or fraud campaigns linked to these groups.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A 22-country enforcement action against Black Axe and similar networks signals growing international pressure on cyber fraud groups; useful background for board-level threat landscape briefings, but no immediate organizational action required.&lt;/li>
&lt;/ul></description></item><item><title>Ransomware affiliate poses as recovery firm to double-extort victims</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-rogue-ransomware-affiliate-poses-as-recovery-firm-to-steal-p/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-rogue-ransomware-affiliate-poses-as-recovery-firm-to-steal-p/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Awareness of this double-extortion tactic helps analysts brief IR teams and counsel victims to verify recovery vendor legitimacy before engaging; no IOCs or detection surface provided.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your org ever faces ransomware, pre-vet legitimate recovery firms now and add vendor verification steps to your IR playbook to avoid paying fraudulent intermediaries.&lt;/li>
&lt;/ul></description></item><item><title>ToxicPanda 2.0 Android Malware Expands Targeting with 167 Remote Commands</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-toxicpanda-2-0-and-golddigger-expand-android-banking-attacks/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-toxicpanda-2-0-and-golddigger-expand-android-banking-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No infrastructure or cloud exposure here; this is a mobile banking trojan. Worth understanding the PIN-harvesting technique if your org develops mobile banking apps, but no patch or configuration action required.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs published in this item, but the expanded 140+ targeted app list and new remote-command capability warrant building or tuning mobile threat detections; review Zimperium&amp;rsquo;s full report for indicators to add to mobile MDM alerting.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Relevant if your org operates a banking or crypto app; file as emerging mobile fraud risk for the next risk-register review, but no immediate board-level action indicated without corroborating incident data.&lt;/li>
&lt;/ul></description></item><item><title>OpenAI Disrupts Cambodia-Based Scam Network Using ChatGPT</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-openai-disrupts-poipet-scam-network-using-chatgpt-across-mul/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-openai-disrupts-poipet-scam-network-using-chatgpt-across-mul/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Documents how AI-assisted fraud operations leverage LLM accounts for scalable scam content generation; no IOCs or detection surface provided, but useful context for understanding AI-enabled social engineering at scale.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates the emerging risk of AI platforms being weaponized by organized fraud networks; useful context for board-level discussions on AI usage policies and third-party AI tool risk.&lt;/li>
&lt;/ul></description></item><item><title>Apple sued over fake crypto wallet app stealing $1.8M in Bitcoin</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-apple-sued-over-fake-app-store-crypto-wallet-app-stealing-1/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-apple-sued-over-fake-app-store-crypto-wallet-app-stealing-1/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A lawsuit claiming Apple failed to prevent a fraudulent app from reaching consumers highlights platform vetting risk; useful context if your organization relies on mobile app stores for software distribution or if customers use your brand name in mobile apps.&lt;/li>
&lt;/ul></description></item><item><title>Spanish Police dismantle €140M BEC and investment fraud ring</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-spanish-police-take-down-140-million-cyber-fraud-ring-arrest/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-spanish-police-take-down-140-million-cyber-fraud-ring-arrest/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> BEC at this scale is a useful reminder to review email authentication controls and employee awareness, but no IOCs or TTPs are published from this takedown.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A €140M fraud operation highlights BEC as a material financial risk; useful context for board-level discussions on business email compromise exposure and vendor payment controls.&lt;/li>
&lt;/ul></description></item></channel></rss>