AntiMalwareAugust 11, 2026🇷🇺Translated from Russian

Mail.ru Blocks Phishing Wave Using Password-Protected RAR Archives

Mail.ru's antispam team has disrupted a fresh phishing campaign that distributes malicious files inside password-protected RAR archives. Over the past month these messages represented 13% of all emails blocked by the service.

The scheme targets both home users and small and medium-sized businesses. Attackers send messages that appear to contain contracts, requests for document signatures, or notifications about regulatory matters. The emails reference federal laws, maintain a formal tone, and urge recipients to examine the attachment immediately.

To increase credibility, the password for the archive is included directly in the body of the message. Once opened, the archive reveals an executable file that installs malware capable of stealing credentials, establishing remote access, or exfiltrating sensitive personal and corporate information.

The timing of the campaign coincides with the period when companies submit tax and quarterly reports involving VAT, personal income tax, and other mandatory filings. In this busy environment, an archive bearing an official-sounding name is more likely to be opened without suspicion.

Mail.ru's email security system examines every message with more than 30 machine-learning models and antispam filters. The platform also verifies senders and marks confirmed organizations with a green shield indicator.

Security specialists recommend that users avoid opening attachments under time pressure, carefully check the sender's address, and never execute files received from unexpected sources even when a password is provided in the same message.

Related articles

AntiMalwareFraud & Social Engineering

Kaspersky Adds Call Filtering to Kaspersky Secure Mobility Management for Android Devices

Kaspersky has introduced call control capabilities into the expanded version of Kaspersky Secure Mobility Management. The new feature allows corporate Android devices running Kaspersky Endpoint Security for Android to check incoming call numbers against both local offline databases and global online reputation sources. Depending on company policy, the system can display warnings to employees or automatically block suspicious calls. Administrators gain the ability to define rules by call category, maintain black and white lists, and apply different policies to specific employee groups. The update targets risks from telephone fraud and social engineering attempts that aim to extract confidential corporate information or funds. It also helps reduce unwanted spam calls that disrupt staff who handle high volumes of incoming communications. Kaspersky Secure Mobility Management provides full lifecycle control over corporate mobile devices, applications, data, and security policies.

HabrFraud & Social Engineering

Behavioral Anti-Fraud: How Systems Analyze User Actions Beyond Device and Browser Fingerprints

Anti-fraud systems are shifting from static device and browser fingerprinting toward continuous behavioral analysis powered by machine learning. The article explains why matching User-Agent strings with Canvas or font rendering is no longer sufficient, as bot developers can easily synchronize these static signals. Modern defenses now record dozens of micro-events during a session, including keystroke timing, mouse trajectories, scroll speed, and focus changes, to build a dynamic Trust Score. These models are trained on large clusters of real-user behavior and flag sessions whose patterns fall outside legitimate clusters even when fingerprints appear realistic. The text details dwell time, flight time, error-correction patterns, natural hand tremor, and acceleration curves governed by Fitts’s law as key biometric markers. It also covers browser-level signals such as Event.isTrusted, CDP artifacts, and navigator.webdriver flags that reveal automation frameworks. The discussion extends to mobile sensors and concludes that perfectly error-free, mathematically smooth input is itself a strong indicator of synthetic activity.

BoletimSecFraud & Social Engineering

Free Online Panel Examines Rising Omnichannel Scams and Multichannel Fraud Tactics

The Brazilian human risk management firm Eskive is hosting its third free online panel on August 18 at 11 a.m. to address the growing threat of omnichannel cyber fraud. Experts will discuss how attackers combine multiple channels such as email, SMS, and other vectors to create more convincing social-engineering narratives that bypass traditional single-channel defenses. The event will feature CEO Priscila Meyer as moderator along with cyber threat intelligence specialist Thiago Bordini and Santa Catarina Civil Police investigator Elias Edenis. Participants will gain practical insights from real client simulations, live Q&A sessions, and interactive quizzes designed to improve organizational preparedness. The panel aims to highlight why users accustomed to recognizing basic phishing or smishing attempts remain vulnerable when fraudsters deploy coordinated, multi-channel campaigns.

BoletimSecFraud & Social Engineering

OpenAI Disables Coordinated ChatGPT Network Used for Financial Scams and Identity Forgery

OpenAI has deactivated a coordinated network of ChatGPT accounts that supported financial fraud, romance scams, and identity forgery operations. Criminals leveraged the AI to generate fake personas, translate conversations, and craft targeted messages aimed at victims across multiple schemes. The investigation originated from reports of suspicious activity observed on WhatsApp. Scammers used the tool to produce forged documents including stock confirmations, legal notices, passports, and fake financial interfaces to increase credibility. Operations typically began on social media or messaging apps, building emotional trust or urgency before requesting deposits, activation fees, or nonexistent fines. Indicators of possible human trafficking and forced labor were also uncovered through job advertisements and internal discussions about worker control in Poipet. OpenAI has blocked the accounts and shared operational indicators with law enforcement and technology companies.