AntiMalwareSeptember 8, 2026🇷🇺Translated from Russian

Free Robux Lures Used in Phishing Campaign Targeting Children's Messenger Accounts

Scammers have launched a new wave of attacks targeting children and teenagers by promising free in-game currency for popular titles including Roblox, Brawl Stars, and Standoff 2. Instead of delivering rewards, the criminals hijack accounts in popular messengers. The scheme was identified by specialists from F6.

The bait is distributed through short videos on YouTube. Video creators, sometimes posing as popular bloggers, promote daily giveaways of Robux, gems, and gold. Viewers are instructed to follow a link from the creator’s profile, which leads directly into a phishing operation.

One of the fraudulent sites is styled as the brand NovaDrop. Users first select a messenger and a game, read fabricated positive reviews, and then reach a roulette page. The wheel predictably awards a large prize of 25,000 coins. To collect the winnings, the child is asked to prove they are human by providing a phone number and entering a six-digit code.

In reality, the code is used to complete authentication in the selected messenger. Attackers thereby gain full access to the account. They can read private conversations, view documents, photographs, videos, and contact lists, then quietly send messages to the victim’s friends. In some cases the owner continues using the account without noticing the intrusion, while in others the account is fully taken over.

According to F6, the criminals are intensifying efforts to steal existing profiles because of growing difficulties in purchasing new Russian accounts for their fraudulent campaigns.

Related articles

HabrFraud & Social Engineering

Dynamic QR Codes Enable Personalized Redirects and Conceal Final Destinations

Dynamic QR codes printed on menus, receipts, and advertisements do not contain the final destination URL. Instead they point to an intermediary service that logs each scan and issues a redirect chosen at scan time. The redirect decision can depend on device model, language, IP address, country, and previous scans, allowing different users to receive entirely different pages. Owners can change the target after printing without replacing the physical code, creating risks when domains or accounts change hands. Each scan records time, device details, and approximate location, leaving a trail users did not consent to. Attackers exploit these properties with overlay stickers, QR codes inside documents that bypass email filters, and fake payment pages that request card details instead of processing a true QR payment.

AntiMalwareFraud & Social Engineering

Booking.com Security Overlooked Fake Downing Street Listing in Which? Fraud Test

Researchers from Which? successfully listed a fake apartment at 10 Downing Street on Booking.com to test the platform's fraud defenses. The listing included the exact address, photos of the UK Prime Minister's residence, and a description of a one-bedroom property near Parliament. Booking.com processed a payment for a week-long stay and failed to refund it even after more than six weeks. A fabricated positive review mentioning the official cat Larry was approved almost instantly. The platform also permitted a phishing link sent through its internal chat system asking for credit card details. The listing remained active from June 18 until its removal on August 27, prompting Which? to call for an Ofcom investigation into Booking.com's systemic security failures.

BoletimSecFraud & Social Engineering

Password Spraying Campaign Targets AWS Root Accounts in Over 150 Organizations

A password spraying campaign targeted AWS root accounts across more than 150 organizations between July 24 and August 23, 2026. Attackers performed repeated login attempts against identities holding maximum privileges in the cloud environment. The root account is created with every AWS account and grants full access to resources, configurations, billing, and sensitive administrative functions. Researchers observed a median of two attempts per organization, with some targets receiving up to eight attempts. No successful authentications linked to the campaign have been identified so far. The attacks leveraged distributed proxies across multiple countries and networks, including hosting infrastructure and residential proxies, while using user agents that mimicked older versions of Microsoft Edge and Firefox. Since June 2025, AWS has required MFA for root users, significantly raising the bar for account takeover even if a password is discovered.

AntiMalwareFraud & Social Engineering

Unsolicited iPhone 15 Pro Max Delivery to Reddit User Sparks Fears of Targeted Cyber Attack

A Reddit user received an unexpected iPhone 15 Pro Max in a sealed box that was never ordered. Apple’s service identified the serial number as belonging to a device purchased or activated in December 2023, with its warranty already expired in 2024, creating a clear mismatch between the new-looking packaging and the device’s documented history. The included FedEx label contained a tracking number that does not exist in the carrier’s system. Discussion on the platform raised the possibility of a targeted attack, potentially a form of whaling, in which the phone could have been pre-modified to steal data or credentials once connected to a network or Apple ID. No concrete evidence confirms the package originated from an attacker, and alternative explanations such as a delivery error or order fraud remain possible. Experts recommend that recipients avoid powering on the device, inserting a SIM card, or entering any account credentials, and instead consider returning it to Apple for inspection or disposing of it as electronic waste.