Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Category

Campaign Analysis

Specific phishing campaigns, actor activity, and the lures and chains behind them.

Methods Watch

4 tracked methods

Rising

Selective Payload Delivery

Geofencing, user-agent checks, host profiling, and manual validation before payload release.

Red Team Lens
Model decision points and target validation during emulation.
Blue Team Lens
Preserve full redirect chains, request metadata, attachment hashes, and post-click endpoint behavior.
Read the note

Persistent

User-Driven Execution

Fake setup, verification, troubleshooting, and support flows that convince users to run commands.

Red Team Lens
Test whether training and guardrails hold when the prompt looks like routine work.
Blue Team Lens
Watch browser-to-shell handoffs, clipboard-to-terminal patterns, script interpreters, and unusual child processes.
Read the note

Accelerating

Trusted Workflow Abuse

Developer packages, SaaS integrations, RMM tools, and legitimate infrastructure used as delivery or persistence paths.

Red Team Lens
Emulate trust abuse with approved fixtures and clear collection boundaries.
Blue Team Lens
Correlate package installs, OAuth grants, deploy tokens, remote tools, and identity events after suspicious activity.
Read the note

Durable

Mailbox and Identity Reuse

Harvested credentials or sessions used to read mail, map relationships, and send more credible lures.

Red Team Lens
Exercise reply-chain and help-desk pretexts without collecting sensitive content.
Blue Team Lens
Detect mailbox rule changes, impossible travel, risky OAuth grants, session replay, and unusual internal sending.
Read the note

Campaign Analysis Archive

13 entries

Field Analysis

Dual UseCampaign AnalysisJun 7, 20267 min read

SHub Reaper Drops Terminal-Based ClickFix for an AppleScript URL Pivot

SentinelOne's writeup of the SHub Reaper macOS stealer shows the ClickFix family adapting to platform hardening. When macOS Tahoe 26.4 closed the Terminal-based path, the operators moved to the applescript:// URL scheme and Script Editor instead.

Read more:SentinelOneBleepingComputer

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #macOS

Field Analysis

Blue TeamCampaign AnalysisMay 31, 20266 min read

FortiClient EMS Abuse Shows Why Management Planes Are Credential-Theft Surface

Recent exploitation of CVE-2026-35616 turned FortiClient EMS into a malware delivery channel, pushing an EKZ credential stealer through trusted endpoint management paths.

Read more:Arctic WolfArctic Wolf

By PhishPond Desk

  • #Campaign Analysis
  • #Credential Theft
  • #Endpoint Management

Field Analysis

Dual UseCampaign AnalysisMay 31, 20266 min read

Ghost CMS ClickFix Wave Turns Trusted Sites Into Paste-and-Run Staging

A reported exploitation wave against Ghost CMS pushed malicious JavaScript onto more than 700 sites, sending visitors into fake verification flows that used ClickFix-style paste-and-run instructions.

Read more:The Hacker NewsMalwarebytes Labs

By PhishPond Desk

  • #Campaign Analysis
  • #ClickFix
  • #Web Compromise

Field Analysis

Blue TeamCampaign AnalysisMay 31, 20267 min read

Phishing the Recovery Key: Fake Signal Support Goes After Encrypted Backups

A phishing wave impersonating Signal Support pressures targets to hand over the 64-character recovery key that protects their encrypted backups, harvesting a secret directly inside the trusted app with no link to detonate.

Read more:TechCrunchMalwarebytes

By PhishPond Desk

  • #Campaign Analysis
  • #Signal
  • #Social Engineering

Field Analysis

Dual UseCampaign AnalysisMay 20, 202610 min read

Breaking Down the Code of Conduct Campaign: PDF Lures, CAPTCHA Gates, and AiTM Token Theft

Microsoft detailed an April 2026 campaign that wrapped credential theft in HR disciplinary language, used a CAPTCHA as an anti-analysis gate, and stole tokens through an adversary-in-the-middle proxy.

Read more:Microsoft Security BlogThe Hacker News

By PhishPond Desk

  • #Campaign Analysis
  • #AiTM
  • #Token Theft

Field Analysis

Blue TeamCampaign AnalysisMay 6, 20268 min read

Compliance Lures Are Becoming Multi-Stage AiTM Token Traps

Recent code-of-conduct phishing campaigns show how attackers blend HR pressure, PDF staging, CAPTCHA gates, and AiTM flows to steal session tokens.

Read more:Microsoft Security BlogMicrosoft Security Blog

By PhishPond Desk

  • #AiTM
  • #Credential Theft
  • #CAPTCHA

Field Analysis

Blue TeamCampaign AnalysisMay 6, 202612 min read

Research Note: Octo Tempest and Scattered Spider Show Why Help Desk Identity Is Attack Surface

Actor reporting on Octo Tempest and Scattered Spider shows how phishing, help desk social engineering, MFA reset abuse, and remote access tooling combine into identity-first intrusion chains.

Read more:CISAMicrosoft Security Blog

By PhishPond Desk

  • #Scattered Spider
  • #Octo Tempest
  • #Help Desk

Field Analysis

Blue TeamCampaign AnalysisMay 5, 202613 min read

Storm-1747 and the Tycoon 2FA Operator Class: A Defender Brief

Storm-1747 sells Tycoon 2FA - one of the most prolific reverse-proxy phishing kits in current circulation. This brief is what a defender team needs to know about the operator class.

Read more:Microsoft Threat IntelligenceSekoia

By PhishPond Desk

  • #Storm-1747
  • #Tycoon 2FA
  • #AitM

Field Analysis

Red TeamCampaign AnalysisApr 24, 20269 min read

Approval Fatigue Becomes the New Credential Theft Front Door

Attackers are blending push prompts, urgent collaboration lures, and identity fatigue to move users from suspicion to accidental approval.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #Push Fraud
  • #OAuth
  • #Identity

Field Analysis

Red TeamCampaign AnalysisApr 23, 202611 min read

Developer Tooling Compromise Turns Trusted Packages Into Phishing Surface

Recent package compromises show how developer trust can be abused to harvest credentials and seed downstream phishing risk.

Read more:BleepingComputerCISA

By PhishPond Desk

  • #Supply Chain
  • #Developer Security
  • #Credential Theft

Field Analysis

Red TeamCampaign AnalysisApr 22, 20269 min read

Ai-Powered Invoice Lures Shift to Thread-Hijacked Supplier Mailboxes

Enterprise responders are seeing invoice fraud migrate from bulk spoofing to thread-hijacking and linguistically adaptive payloads.

Read more:BleepingComputerKrebsOnSecurity

By PhishPond Desk

  • #BEC
  • #Supplier Fraud
  • #Thread Hijacking

Field Analysis

Red TeamCampaign AnalysisApr 19, 202610 min read

Phone-Plus-Teams to Token Persistence: Storm-1811's External-Chat Phishing Chain

Storm-1811 chained voice phishing, Microsoft Teams external chats, and Quick Assist into a remote-control persistence path that ended in Black Basta deployments. Here is the chain step by step.

Read more:Microsoft Threat IntelligenceRapid7

By PhishPond Desk

  • #Storm-1811
  • #Vishing
  • #Microsoft Teams

Field Analysis

Blue TeamCampaign AnalysisApr 15, 20269 min read

ClickFix and Fake-CAPTCHA Paste-and-Run: From 2024 Variant to 2026 Default Stage-One

What started as a niche fake-CAPTCHA gimmick became one of 2026's most common stage-one execution pivots. This is what defenders are seeing in telemetry and what the response patterns look like.

Read more:Microsoft Threat IntelligenceProofpoint

By PhishPond Desk

  • #ClickFix
  • #Threat Trends
  • #Detection Engineering

Explore Other Categories

  • Tradecraft Labs
  • Infrastructure Intelligence
  • Detection & Validation
  • Research Reports