Find notable cyber news and cases, enriched with sources, timelines, and signals.

SeasonalInvite eCard phishing campaign targeting Windows and macOS users

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

The SeasonalInvite phishing campaign has been active for six months, tricking Windows and macOS users into installing legitimate RMM software through fake eCards. The operation used 959 domains and a traffic distribution system (TDS) to route victims to a BlueMountain impersonation page that auto-downloaded an installer. The campaign matters because the installers were commercially signed and therefore could pass normal security checks while still enabling attacker-controlled remote access.

Related Happenings

Operation BlueDash Microsoft Teams phishing campaign delivering Level RMM and ScreenConnect

Campaign
H score45 First: 27.07.2026 15:37 Last: 27.07.2026 15:37 Sources 1

About this happening: The Operation BlueDash phishing campaign is using a fake Microsoft Teams update flow to install Level RMM and ConnectWise ScreenConnect, creating persistent remote...

Mexico CURP lure .NET infostealer delivery

Malware Activity
H score21 First: 20.07.2026 20:29 Last: 20.07.2026 20:29 Sources 1

About this happening: A .NET infostealer delivery operation now threatens Windows users in Mexico by using a CURP typosquat and WebDAV path abuse to reach victims. The payload arrived t...

Gobf[.]mx CURP typosquat phishing campaign targeting Mexican users

Campaign
H score25 First: 20.07.2026 20:29 Last: 20.07.2026 20:29 Sources 1

About this happening: The gobf[.]mx operation used a CURP typosquat, a fake record-retrieval page, and WebDAV delivery to push malware at Windows users in Mexico, creating a live phishi...

SleeperGem RubyGems supply-chain campaign

Campaign
H score17 First: 20.07.2026 08:15 Last: 20.07.2026 08:15 Sources 1

About this happening: SleeperGem is an active RubyGems supply-chain campaign that used three malicious gems to stage second payloads, evade CI environments, and persist on developer m...

CrashStealer meeting-PIN delivery campaign

Campaign
H score35 First: 13.07.2026 22:04 Last: 13.07.2026 22:04 Sources 1

About this happening: The CrashStealer campaign is delivering a signed, Apple-notarized installer from a fake software site gated by a meeting PIN, narrowing infection opportunities to...

Timeline

  1. 15.07.2026 18:00 2 articles · 13d ago

    SeasonalInvite eCard phishing campaign targeting Windows and macOS users

    Initial Disclosure

    Early activity used tax and Social Security lures, then rotated to Valentine's, Easter, and spring invitation themes. Victims who reached the fake greeting-card page were funneled through a TDS to an installer that matched their operating system.

    Show sources