CERT-UA links the AgingFly credential-stealing campaign to phishing, browser theft, and modular remote access.
PHANTOMPULSE spreads via Obsidian plugin abuse in REF6598 campaign, targeting finance and crypto users, bypassing AV controls ...