# Threat Intel

Published articles for Threat Intel.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Fake parcel delivery messages steal your card and bank details

DevFeed: [Fake parcel delivery messages steal your card and bank details](<https://devfeed.tech/articles/fake-parcel-delivery-messages-steal-your-card-and-bank-details-42790.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/scams/2026/09/fake-parcel-delivery-messages-steal-your-card-and-bank-details>)

Author: Mieke Verburgh

Published: 2026-09-18T07:44:22Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [online privacy](<https://devfeed.tech/topics/online-privacy.md>)

Tags: [banking](<https://devfeed.tech/tags/banking.md>), [card](<https://devfeed.tech/tags/card.md>), [delivery](<https://devfeed.tech/tags/delivery.md>), [email](<https://devfeed.tech/tags/email.md>), [financial](<https://devfeed.tech/tags/financial.md>), [personal](<https://devfeed.tech/tags/personal.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The article describes parcel-delivery phishing campaigns that impersonate postal and courier services. A Belgian bpost campaign uses a small unpaid-customs-fee claim to direct victims to a fake website that collects personal, card, and banking information.

### Source excerpt

Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.

## Revolut phishing texts appear days after data breach

DevFeed: [Revolut phishing texts appear days after data breach](<https://devfeed.tech/articles/revolut-phishing-texts-appear-days-after-data-breach-42143.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach>)

Author: Pieter Arntz

Published: 2026-09-17T14:07:15Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [VirusTotal](<https://devfeed.tech/topics/virustotal.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [breach](<https://devfeed.tech/tags/breach.md>), [password](<https://devfeed.tech/tags/password.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [revolut](<https://devfeed.tech/tags/revolut.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Revolut customers received phishing texts days after the bank disclosed customer data to a government impostor. The report says the campaign's connection to the breach is not yet known and describes a fake identity check designed to obtain passwords.

### Source excerpt

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

## T-Mobile rewards points expiry texts are a phishing scam

DevFeed: [T-Mobile rewards points expiry texts are a phishing scam](<https://devfeed.tech/articles/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam-41305.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam>)

Author: Pieter Arntz

Published: 2026-09-17T10:44:01Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [account](<https://devfeed.tech/topics/account.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [customer](<https://devfeed.tech/tags/customer.md>), [links](<https://devfeed.tech/tags/links.md>), [messages](<https://devfeed.tech/tags/messages.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [points](<https://devfeed.tech/tags/points.md>), [reward-points](<https://devfeed.tech/tags/reward-points.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [t-mobile](<https://devfeed.tech/tags/t-mobile.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Malwarebytes reports a phishing campaign that sends fake T-Mobile rewards-point expiry messages. The messages use invented balances, urgent expiry dates, and phishing links to pressure recipients into clicking before verifying the claim.

### Source excerpt

A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

## AI helps scammers build convincing antivirus renewal pages

DevFeed: [AI helps scammers build convincing antivirus renewal pages](<https://devfeed.tech/articles/ai-helps-scammers-build-convincing-antivirus-renewal-pages-30921.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages>)

Author: Stefan Dasic

Published: 2026-09-16T08:41:19Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [remote access software](<https://devfeed.tech/topics/remote-access-software.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [remote-access-software](<https://devfeed.tech/tags/remote-access-software.md>), [scams](<https://devfeed.tech/tags/scams.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The article examines an Avast impersonation site targeting users in Belgium with a fake EUR 129.99 antivirus renewal notice. It reports that the polished design and fluent copy showed signs of AI assistance, while a cancellation form collected names, email addresses, and Belgian mobile numbers for possible follow-up scams.

### Source excerpt

A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.

## Search results are sending people to fake Bitrefill checkouts

DevFeed: [Search results are sending people to fake Bitrefill checkouts](<https://devfeed.tech/articles/search-results-are-sending-people-to-fake-bitrefill-checkouts-26613.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts>)

Author: Stefan Dasic

Published: 2026-09-15T08:40:22Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cryptocurrency](<https://devfeed.tech/topics/cryptocurrency.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Website](<https://devfeed.tech/topics/website.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [cryptocurrency](<https://devfeed.tech/tags/cryptocurrency.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [payments](<https://devfeed.tech/tags/payments.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [qr-code](<https://devfeed.tech/tags/qr-code.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [search](<https://devfeed.tech/tags/search.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

Fake Bitrefill checkout pages are appearing in search results and copying the company's branding and payment flow. They persuade victims to send cryptocurrency to scammer-controlled addresses, with no goods delivered and little chance of recovering the payment.

### Source excerpt

Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.

## Flirty OnlyFans promoters on X may be using AI to appear human

DevFeed: [Flirty OnlyFans promoters on X may be using AI to appear human](<https://devfeed.tech/articles/flirty-onlyfans-promoters-on-x-may-be-using-ai-to-appear-human-8430.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/ai/2026/09/flirty-onlyfans-promoters-on-x-may-be-using-ai-to-appear-human>)

Author: Pieter Arntz

Published: 2026-09-07T11:18:00Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [AI Chat](<https://devfeed.tech/topics/ai-chat.md>), [Script](<https://devfeed.tech/topics/script.md>), [Chat Bot](<https://devfeed.tech/topics/chatbot.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [ASCII](<https://devfeed.tech/topics/ascii.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ascii](<https://devfeed.tech/tags/ascii.md>), [bots](<https://devfeed.tech/tags/bots.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [messaging](<https://devfeed.tech/tags/messaging.md>), [onlyfans](<https://devfeed.tech/tags/onlyfans.md>), [scam](<https://devfeed.tech/tags/scam.md>), [scams](<https://devfeed.tech/tags/scams.md>), [scripted](<https://devfeed.tech/tags/scripted.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [voice](<https://devfeed.tech/tags/voice.md>)

### AI overview

An investigation examines X accounts promoting OnlyFans pages that combine repetitive flirtatious scripts with dynamic replies, raising the possibility of generative AI-assisted messaging. It warns that personalized responses and voice notes may no longer reliably distinguish people from automated accounts.

### Source excerpt

Personalized replies and voice notes make it increasingly difficult to tell whether you're talking to a human, chatbot, or AI agent.

## StreamRat Android malware spreads through Meta and TikTok ads

DevFeed: [StreamRat Android malware spreads through Meta and TikTok ads](<https://devfeed.tech/articles/streamrat-android-malware-spreads-through-meta-and-tiktok-ads-8441.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads>)

Author: Pieter Arntz

Published: 2026-09-03T16:04:24Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [advertising](<https://devfeed.tech/tags/advertising.md>), [android](<https://devfeed.tech/tags/android.md>), [browser](<https://devfeed.tech/tags/browser.md>), [malware](<https://devfeed.tech/tags/malware.md>), [meta](<https://devfeed.tech/tags/meta.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [streamrat](<https://devfeed.tech/tags/streamrat.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [tiktok](<https://devfeed.tech/tags/tiktok.md>)

### AI overview

A malicious ad campaign used fake streaming-service promotions on Meta and TikTok to distribute the StreamRat Android banking Trojan. The campaign directed Android users to a tailored download page that coached them past security warnings and enabled credential theft and remote device control.

### Source excerpt

Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

## DNS Security

DevFeed: [DNS Security](<https://devfeed.tech/articles/dns-security-36761.md>)

Original publisher: [Read original article](<https://shostack.org/blog/dns-security/>)

Author: Adam

Published: 2019-06-13T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [DNS security](<https://devfeed.tech/topics/dns-security.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cyber](<https://devfeed.tech/tags/cyber.md>), [deploy](<https://devfeed.tech/tags/deploy.md>), [dns](<https://devfeed.tech/tags/dns.md>), [dns-security](<https://devfeed.tech/tags/dns-security.md>), [easy](<https://devfeed.tech/tags/easy.md>), [effective](<https://devfeed.tech/tags/effective.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>)

### AI overview

The Global Cyber Alliance published research by Jay Jacobs, Wade Baker, and the author on the value of DNS security. The article says DNS providers using threat intelligence to block malicious sites can be effective and easy to deploy, citing a report that says DNS security can mitigate one-third of cyber incidents.

### Source excerpt

I'm happy to say that some new research by Jay Jacobs, Wade Baker, and myself is now available, thanks to the Global Cyber Alliance.