<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Phishing on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/phishing/</link><description>Recent content in Phishing on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Wed, 01 Jul 2026 13:25:22 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/phishing/index.xml" rel="self" type="application/rss+xml"/><item><title>Phantom Squatting Lets Hackers Buy the Fake Websites Your AI Invents</title><link>https://hackingpassion.com/phantom-squatting-ai-domains/</link><pubDate>Wed, 01 Jul 2026 13:25:22 +0200</pubDate><guid>https://hackingpassion.com/phantom-squatting-ai-domains/</guid><description>&lt;p>Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people type in.&lt;/p>
&lt;p>You trust the link because it came from your AI. That trust is the attack itself, and it works without a single phishing email.&lt;/p>
&lt;p>It has a name now: &lt;strong>phantom squatting&lt;/strong>. Security researchers wrote it up this week. The idea is simple once you see it.&lt;/p></description></item><item><title>WinRAR Can Still Drop Malware Into Your Startup Folder a Year After the Patch</title><link>https://hackingpassion.com/winrar-rar-startup-folder-attack/</link><pubDate>Tue, 30 Jun 2026 11:05:19 +0200</pubDate><guid>https://hackingpassion.com/winrar-rar-startup-folder-attack/</guid><description>&lt;p>You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the only thing you did was open an archive someone emailed you.&lt;/p>
&lt;p>In July 2025, ESET researchers spotted a file called &lt;code>msedge.dll&lt;/code> sitting inside a RAR archive, in a folder path that made no sense. That odd path turned out to be a brand new flaw in WinRAR, and someone was already using it in attacks while it was still unknown. That was last summer, and it has not stopped since.&lt;/p></description></item><item><title>Does Google Control Your Email?</title><link>https://hackingpassion.com/does-google-control-your-email/</link><pubDate>Wed, 24 Jun 2026 12:52:27 +0200</pubDate><guid>https://hackingpassion.com/does-google-control-your-email/</guid><description>&lt;p>Anyone on the internet can send an email that looks like it came from your bank, your boss, or you, and the system that delivers it will not check whether that is true.&lt;/p>
&lt;p>The reason is not a bug someone forgot to fix. Email was built in 1982 to trust whoever was talking, back when a few hundred computers were online and the people running them knew each other, and that trust was never taken back out.&lt;/p></description></item><item><title>Microsoft 365 Mailbox Rules Are Being Weaponized</title><link>https://hackingpassion.com/microsoft-365-mailbox-rules-attack/</link><pubDate>Fri, 17 Apr 2026 13:11:20 +0200</pubDate><guid>https://hackingpassion.com/microsoft-365-mailbox-rules-attack/</guid><description>&lt;p>Microsoft 365 mailbox rules are being weaponized as a core technique behind &lt;strong>$2.77 billion in annual Business Email Compromise losses&lt;/strong>, and attackers are creating hidden rules that survive password resets, MFA enrollment, and session invalidation. A new Proofpoint report reveals that &lt;strong>10% of all compromised Microsoft 365 accounts get malicious inbox rules installed within seconds of the initial breach&lt;/strong>, targeting 400+ million users worldwide by abusing built-in email functionality no security tool will ever flag as suspicious. 😏&lt;/p></description></item><item><title>QR Codes: What You Need to Know</title><link>https://hackingpassion.com/qr-codes-what-you-need-to-know/</link><pubDate>Mon, 06 Apr 2026 16:48:56 +0200</pubDate><guid>https://hackingpassion.com/qr-codes-what-you-need-to-know/</guid><description>&lt;p>Yesterday, I posted a QR code challenge on this &lt;strong>&lt;a href="https://www.facebook.com/ethical.hack.group/" target="_blank" rel="noopener noreffer">Ethical Hacking page&lt;/a>&lt;/strong>, and it has since been removed. A cipher, hidden inside a QR code, with three security questions and a prize. The comments that followed gave me a good reason to write about this, because this is a topic that deserves a proper explanation.&lt;/p>
&lt;p>The comments came in fast. &amp;ldquo;You should never scan a random QR code.&amp;rdquo; &amp;ldquo;This is a trap.&amp;rdquo; &amp;ldquo;You failed the first part just by scanning.&amp;rdquo; &amp;ldquo;Hackers know better than to do this.&amp;rdquo; And honestly, that reaction makes sense. You see a QR code on a hacking page, you do not know what is inside it, and being careful is right. But being careful does not mean refusing to engage. It means knowing how to approach it.&lt;/p></description></item><item><title>Fake Blue Screen of Death Installs $5 RAT Malware via ClickFix Attack</title><link>https://hackingpassion.com/fake-bsod-clickfix-dcrat-malware/</link><pubDate>Tue, 06 Jan 2026 15:39:00 +0100</pubDate><guid>https://hackingpassion.com/fake-bsod-clickfix-dcrat-malware/</guid><description>&lt;p>$5 buys two months of complete access to someone&amp;rsquo;s computer. Keylogging, webcam, passwords, files. The malware is called DCRat. The delivery method: a fake Blue Screen of Death that tricks people into hacking themselves. 😱&lt;/p>
&lt;p>ClickFix attacks surged 517% in six months. Now the second most common attack vector after phishing. 8% of all blocked attacks. The campaign is called PHALT#BLYX. Securonix published their analysis January 5, 2026.&lt;/p>
&lt;p>An email arrives with subject &amp;ldquo;Reservation Cancellation.&amp;rdquo; Sender appears to be Booking.com. The message mentions a refund over €1,000 and urges the recipient to click and review. Booking.com has been a popular target before, with similar campaigns in 2023 and 2024.&lt;/p></description></item></channel></rss>