<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vishing on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vishing/</link><description>Recent content in Vishing on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 31 Aug 2026 18:00:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vishing/index.xml" rel="self" type="application/rss+xml"/><item><title>Spring Ring campaign uses Teams voice phishing to hit domain controllers</title><link>https://curasec.metacog.co.kr/insights/2026-08-31-spring-ring-an-inside-look-at-voice-phishing-campaigns-in-mi/</link><pubDate>Mon, 31 Aug 2026 18:00:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-31-spring-ring-an-inside-look-at-voice-phishing-campaigns-in-mi/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE or patch required; the attack path abuses Teams social engineering rather than a software flaw, so review Teams external-access settings and restrict who can initiate calls from outside the tenant.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active enterprise campaign targeting domain controllers via Teams vishing — hunt for anomalous Teams call activity from external tenants followed by process execution or lateral movement, and review Unit 42&amp;rsquo;s published TTPs for detection rule development.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Campaign targets enterprise domain controllers through a trusted communication channel (Teams), raising both breach-risk and vendor-trust questions — brief IT leadership and consider tightening external Teams communication policies this quarter.&lt;/li>
&lt;/ul></description></item><item><title>AnonyMousKIT PhaaS uses voice AI to phish stolen iPhone passcodes</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-pass/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-anonymouskit-phaas-uses-voice-ai-agents-to-phish-iphone-pass/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The use of automated voice AI agents in a PhaaS platform to socially engineer victims is a meaningful escalation in vishing sophistication; no IOCs or enterprise detection surface are available yet, but analysts should track how this technique migrates toward corporate credential theft campaigns.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>UNC6671 Vishing Campaign Targets SaaS Credentials at Financial Firms</title><link>https://curasec.metacog.co.kr/insights/2026-08-09-unc6671-vishing-attacks-target-personal-phones-to-steal-saas/</link><pubDate>Sun, 09 Aug 2026 11:41:42 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-09-unc6671-vishing-attacks-target-personal-phones-to-steal-saas/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> UNC6671 exploits human trust rather than software vulnerabilities, so there is no patch or config fix. The campaign reinforces the value of phishing-resistant (FIDO2) MFA on SaaS to limit what a tricked employee can surrender.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Named actor with defined TTPs (IT help-desk impersonation via personal phone → SaaS credential handover) but no IOCs published yet; build or tune detections for anomalous SaaS logins and new device enrollments, and consider hunting for suspicious authentication spikes in M365 or Google Workspace logs correlated with help-desk ticket activity.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> An active data extortion group is deliberately targeting employees at financial services, private equity, and professional services firms by phone; if your org is in those sectors, brief employees this week on the IT impersonation lure and verify that help-desk identity-verification procedures are documented and enforced.&lt;/li>
&lt;/ul></description></item><item><title>UNC6671 Vishing-AiTM Campaign Targets Financial Services, Enterprise Cloud</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-unc6671-rebrands-multi-brand-vishing-extortion-targets-finan/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active group uses AiTM to bypass MFA on M365 and Okta; implement phishing-resistant FIDO2/hardware-key MFA and tighten Conditional Access or Okta device-trust policies to invalidate intercepted session tokens.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active campaign with mappable TTPs — hunt for anomalous Okta and M365 session activity (unexpected token origins, bulk SharePoint/OneDrive exfil) since May 2026 and pull the GTIG report for infrastructure IOCs tied to Redact, Pink, Helix, and Falcon brands.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Extortion group is actively hitting financial services, private equity, and professional services — if your org falls in these verticals, brief leadership this week on the campaign and verify that helpdesk impersonation and personal-device contact scenarios are covered in your security awareness program.&lt;/li>
&lt;/ul></description></item></channel></rss>