Multiple cybercriminal operations have been reported, each employing distinct tactics to compromise organizations and individuals. These include a large-scale business email compromise (BEC) campaign dubbed 'Scripted Sparrow,' which orchestrated a global siege involving three million emails, and a sophisticated loader attack using fake purchase orders to target manufacturing giants in Italy, Finland, and Saudi Arabia. Another campaign, referred to as 'The Payroll Trap,' leverages fake CAPTCHA pages in a quishing (QR code phishing) scheme to hijack employee paychecks. Additionally, a phishing campaign impersonating ADP was observed, where threat actors used convincing emails and counterfeit login pages to steal employee credentials and personal data.
Further, the cybercriminal ecosystem is seeing notable developments, such as the unmasking of 'Fly,' the secret architect behind the infamous Russian Market, and the formation of an alliance between Qilin, DragonForce, and a declining LockBit ransomware group. These stories highlight the evolving landscape of cybercrime, with actors employing both technical deception and strategic partnerships to maximize their impact against a range of targets worldwide.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A sophisticated loader malware campaign was reported targeting manufacturing companies in Italy, Finland, and Saudi Arabia. The attackers used 'Purchase Order' themed lures, indicating a spear-phishing operation focused on high-value industrial victims.
Researchers identified a new quishing campaign that uses fake CAPTCHA pages as part of a phishing flow targeting employees. The operation appears aimed at stealing payroll credentials or redirecting payroll deposits to hijack paychecks.
A phishing campaign impersonating ADP was observed using urgent emails and a fake ADP login page to collect employee credentials, 2FA codes, and personal information including phone numbers, dates of birth, and Social Security numbers. Submitted data was exfiltrated to the attackers, enabling potential access to payroll and HR accounts.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityonline.info
Open sourcecofense.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.