PhishFort Blog

Our Research and Announcements

Stay informed with our latest blog posts.

Market Trends 3 min read

Crypto Scams: Why the Crypto Industry Is So Vulnerable and How to Stop Them

Discover why the crypto industry is highly exposed to crypto scams, how social engineering attacks exploit risk-seeking users, and how businesses can protect their brands with proactive security.

Read more: Crypto Scams: Why the Crypto Industry Is So Vulnerable and How to Stop Them
Blog

Latest posts

Research 4 min read

AliExpress Is Using Silent WebAudio to Fingerprint Your Browser

A Bluetooth glitch led to an unexpected discovery: AliExpress runs silent WebAudio processing as part of a browser fingerprinting anti-fraud system. Here's what was found and what it means for security and privacy.

Read more: AliExpress Is Using Silent WebAudio to Fingerprint Your Browser
Research 3 min read

Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams

Online puppy scams use stolen photos, fake breeders, and endless "fees" to steal your money and break your heart. Here's exactly how the trap is set and the one rule that protects you.

Read more: Fake Paws, Real Scams: How to Spot and Avoid Online Puppy Scams
Research 4 min read

UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware

UAC-0099 is hijacking trusted apps like Notepad++ and WinRAR through malicious plugins and DLL sideloading. Here's the full infection chain, based on CERT-UA's technical advisory.

Read more: UAC-0099 Weaponizes Notepad++ and WinRAR Plugins to Deliver Malware
Crypto 4 min read

How Impersonation Fuels Gift Card and Crypto Scams

Gift card and crypto scams work because attackers borrow someone else's identity: a celebrity, an investment manager, even a loved one's voice. Here's how the impersonation angle actually plays out.

Read more: How Impersonation Fuels Gift Card and Crypto Scams
Research 2 min read

How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install

A malicious Google Ad leads to a real chatgpt.com link, where a fake "Codex" install command hides a base64 payload that drops the MacSync infostealer. Here's the full chain.

Read more: How a Real ChatGPT Link Delivers Phishing via a Fake Codex Install