A phishing kit targeting the German bank N26.com and exfiltrating the stolen data to a third party hosted phishing panel which in turn immediately sends a push notification to the attacker.
A seemingly rare phishing kit that targets Iran’s Keshavarzi Bank (Agribank) users and steals their login + OTP.
X-SniPer phishing kit even tries to steal the victim’s mobile phone carrier PIN to perform a SIM swap attack to “bypass” 2FA.
The malicious domain restore-metamask.com was used to steal existing crypto wallets of metamask.io users. It also allowed new wallets to be created and cryptocurrencies deposited to the new wallet, but it would ultimately go to the attackers.