<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Phishing on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/phishing/</link><description>Recent content in Phishing on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 12:22:25 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/phishing/index.xml" rel="self" type="application/rss+xml"/><item><title>TA4922 China Phishing Threat Hits UK &amp; Europe</title><link>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-south-africa-valleyrat-atlas-rat/</link><pubDate>Thu, 04 Jun 2026 12:22:25 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-south-africa-valleyrat-atlas-rat/</guid><description>China-linked TA4922 expands phishing attacks to the UK, Germany, Italy and South Africa using ValleyRAT and Atlas RAT malware families.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">The Hacker News</a></p>
<hr>
<p>A China-linked threat actor, TA4922, has expanded its phishing campaigns beyond its previous targets to now include organisations in the UK, Germany, Italy, and South Africa. The group is deploying known malware families including ValleyRAT and Atlas RAT, with a rapidly evolving toolkit suggesting well-resourced, sustained operations. This represents a significant escalation in geographic scope and poses a direct threat to European enterprises.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten email gateway controls to block phishing lures associated with TA4922, and ensure endpoint detection rules cover ValleyRAT (Winos 4.0) and Atlas RAT indicators. Consider hunting for lateral movement or C2 beaconing patterns consistent with these RAT families across cloud-hosted workloads and on-premises infrastructure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa</a></p>
]]></content:encoded></item><item><title>TA4922 Phishing Targets UK, Germany &amp; Italy</title><link>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-valleyrat-atlas-rat/</link><pubDate>Thu, 04 Jun 2026 12:22:25 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/ta4922-china-linked-phishing-uk-germany-italy-valleyrat-atlas-rat/</guid><description>China-linked TA4922 expands phishing attacks to UK, Germany, Italy and South Africa, deploying ValleyRAT and Atlas RAT. What cloud security teams need to k</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">The Hacker News</a></p>
<hr>
<p>A China-linked threat group, TA4922, has significantly expanded its phishing campaigns beyond its previous targets to now include organisations in the UK, Germany, Italy, and South Africa. The group is deploying known remote access trojans including ValleyRAT and Atlas RAT, with a fast-moving operational pace and an evolving malware toolkit. This matters because the expansion into European markets signals a deliberate strategic shift, increasing risk for organisations in these regions.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review email gateway and endpoint detection rules for ValleyRAT (Winos 4.0) and Atlas RAT indicators of compromise, and ensure phishing-resistant MFA is enforced across all cloud console and SaaS access points. Consider threat intelligence feeds covering Chinese APT activity to stay ahead of this group&rsquo;s rapidly evolving malware arsenal.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html">China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa</a></p>
]]></content:encoded></item><item><title>Google DoubleClick Abused to Deliver DesckVB RAT</title><link>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-deskvb-rat-delivery/</link><pubDate>Wed, 03 Jun 2026 16:29:16 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-deskvb-rat-delivery/</guid><description>A new malspam campaign exploits Google&amp;#39;s trusted DoubleClick domain to bypass security tools and deliver the DesckVB remote access trojan to victims.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">The Hacker News</a></p>
<hr>
<p>Attackers are exploiting Google&rsquo;s DoubleClick ad-serving domain as a redirect hop in malicious email campaigns, using its trusted reputation to bypass security filters before delivering the DesckVB remote access trojan. Because many email and web security tools whitelist or deprioritise scrutiny of well-known Google-owned domains, the technique significantly increases the likelihood of successful delivery. Once installed, a RAT gives attackers persistent remote control over the victim&rsquo;s machine.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your email and web proxy security policies to ensure that redirects through trusted domains — including Google-owned properties like DoubleClick — are still subject to full URL chain inspection and sandbox detonation. Consider enforcing policies that follow and evaluate the final destination URL rather than trusting the initial domain at face value.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</a></p>
]]></content:encoded></item><item><title>Google DoubleClick Abused to Deliver DesckVB RAT</title><link>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-d%D0%B5%D1%81kvb-rat-delivery/</link><pubDate>Wed, 03 Jun 2026 16:29:16 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/google-doubleclick-abused-malspam-d%D0%B5%D1%81kvb-rat-delivery/</guid><description>Attackers are exploiting Google&amp;#39;s trusted DoubleClick domain to bypass email security filters and deliver the DesckVB remote access trojan via malspam.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">The Hacker News</a></p>
<hr>
<p>Attackers are exploiting Google&rsquo;s DoubleClick ad-serving domain as a redirect layer in malicious spam emails, using its trusted reputation to bypass security filtering tools before routing victims to attacker-controlled infrastructure that delivers the DesckVB remote access trojan. Because DoubleClick is a widely trusted Google domain, many email and web security products will not flag the initial link as suspicious. This technique is a growing trend of abusing legitimate cloud services to obscure the early stages of an attack chain.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your email and web proxy security controls to ensure they inspect the full redirect chain rather than trusting links solely based on the root domain — allowlisting DoubleClick or similar Google domains without inspecting downstream redirects creates a blind spot. Consider enforcing URL rewriting and sandboxed link-following in your email security gateway, and ensure endpoint detection controls are tuned to flag RAT behaviour post-delivery.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/google-doubleclick-abused-in-new.html">Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</a></p>
]]></content:encoded></item></channel></rss>