Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Oliver Tree’s mother shares heartbreaking post

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

President Trump to headline America’s 250th anniversary celebration after artist declines

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » AI Tools Fuel Brazilian Phishing Scam, Efimer Trojan steals codes from 5,000 victims
Celebrities

AI Tools Fuel Brazilian Phishing Scam, Efimer Trojan steals codes from 5,000 victims

By August 8, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Cybersecurity researchers are turning their attention to new campaigns using website building tools using legitimately generated artificial intelligence (AI) to create replica phishing pages that mimic Brazilian government agencies as part of a financially motivated campaign.

This activity includes creating sites that look like those that mimic the Brazilian Ministry of State Transport and Education. This will ensure that unsuspecting users make unfair payments through the country’s PIX payment system, Zscaler Threatlabz said.

These scam sites are artificially augmented using search engine optimization (SEO) addiction technology to improve your vision, which increases the chances of successful attacks.

“Source code analysis reveals signatures of generative AI tools, including overly explanatory comments to guide developers, non-functional elements that normally work on real websites, and trends such as Tailwindcss styling that are different from traditional phishing kits used by threat actors.

The ultimate goal of the attack is to provide fake forms that collect sensitive personal information, such as the number of Cadastro de Pessoas físicas (CPFs), Brazilian taxpayer identification numbers, and residential addresses.

Cybersecurity

To further improve the legitimacy of the campaign, phishing pages are designed to employ step-by-step data collection by gradually requesting additional information from victims and reflecting the behavior of real websites. The collected CPF numbers are also validated in the backend by APIs created by threat actors.

“The API domains identified during the analysis are registered by threat actors,” Zscaler said. “The API retrieves data associated with the CPF number and automatically populates the phishing page with information linked to the CPF.”

That said, the company noted that attackers could use information to increase the reliability of phishing attempts by obtaining CPF counts and user details through data breaches, or leveraging publicly available APIs using authentication keys.

“These phishing campaigns are currently stealing relatively little money from victims, but using similar attacks can cause much more damage,” Zscaler said.

Mass mailing campaigns will distribute Efimer Trojans to steal codes

Brazil provided a malicious script called Efimer and also became the focus of a malspam campaign in which it impersonates lawyers for major companies to steal victims’ cryptocurrencies. Russian cybersecurity company Kaspersky detected a massware campaign in June 2025, saying early repetition of malware dates back to October 2024 and spread through infected WordPress websites.

“These emails mistakenly claimed that the recipient’s domain name was violated by the sender’s rights,” said researchers Vladimir Gursky and Artem Ushkov. “This script also includes additional features that help attackers spread even further by breaching their WordPress site and hosting malicious files, among other techniques.”

In addition to propagating through compromised WordPress sites and email, Efimer also utilizes malicious torrents as distribution vectors while communicating with command and control (C2) servers over the TOR network. Additionally, malware can extend functionality with brute force passwords on WordPress sites and additional scripts that allow you to harvest email addresses from websites designated for future email campaigns.

“Script receives domains [from the C2 server] And then repeat each and find the hyperlink and email address on the website page,” Kaspersky said. It also says it will serve as a spam module designed to fill out contact forms on target websites.

In the attack chain documented by Kaspersky, emails are equipped with a ZIP archive that contains another password-protected archive that contains an empty file with a name that specifies the password to open the password. Inside the second zip file is a malicious Windows Script File (WSF) that infects the machine with Efimer upon startup.

At the same time, the victim will receive an error message indicating that the document cannot be opened on the device as a distraction mechanism. In fact, the WSF script saves two other files, “Controll.js” (the Trojan component) and “Controller.xml”, using the configuration extracted from “Controller.xml”, and creates a scheduled task on the host.

Identity Security Risk Assessment

“controller.js” is clipper malware designed to replace cryptocurrency wallets using wallet addresses under attacker control. You can also capture and run additional payloads received from the C2 server by installing the TOR proxy client on an infected computer and connecting over the TOR network.

Kaspersky also incorporates a web browser with anti-VM features like Google Chrome along with the Clipper feature, and also discovered a second version of Efimer that scans Cryptocurrency Wallet Extensions related to atoms, electricity, and escape, and excludes results from searches that return to C2 servers.

The campaign is estimated to have affected 5,015 users based on telemetry, with the majority of infections concentrated in Brazil, India, Spain, Russia, Italy, Germany, the UK, Canada, France and Portugal.

“The main goal is to steal and exchange cryptocurrency wallets, but you can also leverage additional scripts to compromise your WordPress site and distribute spam,” the researcher said. “This allows us to establish a fully malicious infrastructure and spread it to new devices.”

“Another interesting feature of this Trojan horse is its attempt to propagate both individual users and the corporate environment. In the first case, it is said that the attacker will use torrent files as bait and download popular films.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenai’s price GPT-5 is very low and can cause a price war
Next Article Pinterest CEO says agent shopping is still a long way to go

Related Posts

Rama Dowaj Styles Upcycled Knicks Shirt by Claire Sullivan

June 18, 2026

New York Knicks’ most stylish players

June 18, 2026

The meaning behind Michelle Obama’s vintage photo skirt

June 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Oliver Tree’s mother shares heartbreaking post

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

President Trump to headline America’s 250th anniversary celebration after artist declines

This 5-year piano learning app offer has been reduced to just $68, making it cheaper than ever.

Trending Posts

Oliver Tree’s mother shares heartbreaking post

June 19, 2026

FKA Twigs and Lil Yachty lead this week’s Best New Music: Friday Music Guide

June 19, 2026

Taylor Swift completed ‘Toy Story 5’ song in ‘hectic’ 8 hours

June 18, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.