Email attacks follow a systematic multi-stage attack chain from phishing through account compromise to financial fraud; traditional filters are insufficient.
The state administration of Saxony-Anhalt recorded 30 registered IT security incidents in H1 2026, more than double the prior-year period, led by phishing and DDoS attacks.
The German Federal Criminal Police Office (BKA) shut down the Kratos phishing platform, which orchestrated approximately 15,000 phishing campaigns monthly.
A compromised malware delivery server exposed an AI-assisted phishing infrastructure actively deployed against end users, providing insights into operationalization processes and automation techniques.
German and US authorities have shut down the phishing service Kratos, which enabled over 1,800 criminal users to conduct approximately 15,000 campaigns per month, and arrested its operator in Indonesia.
Phishing emails with obfuscated JavaScript lead to fake TTF files that serve as loaders for RATs and information stealers, employing multiple anti-analysis techniques.
Text-salting techniques enable attackers to circumvent AI-driven email filters by embedding hidden text passages in messages that remain undetected by LLMs.