惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
量子位
有赞技术团队
有赞技术团队
博客园 - 三生石上(FineUI控件)
博客园 - Franky
M
MIT News - Artificial intelligence
U
Unit 42
Last Week in AI
Last Week in AI
酷 壳 – CoolShell
酷 壳 – CoolShell
The Cloudflare Blog
J
Java Code Geeks
V
Visual Studio Blog
Engineering at Meta
Engineering at Meta
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
MyScale Blog
MyScale Blog
T
Tailwind CSS Blog
T
The Blog of Author Tim Ferriss
V
V2EX

DomainTools Investigations | SecuritySnacs

Cybersecurity Reading List - Week of 2026-08-17 SecuritySnack - Account Farmers and Sellers Scarcity Scams SecuritySnack - Hijacking Corporate Sessions Cybersecurity Reading List - Week of 2026-06-01 Cybersecurity Reading List - Week of 2026-05-04 DPRK Contagious Interview: Developer Workflow Compromise The AI Frame Campaign Continues Cybersecurity Reading List - Week of 2026-04-06 SecuritySnack - OpenAI Anti-Ads Malware SecuritySnack - CloudFlare Anti-Security For Phishing Cybersecurity Reading List - Week of 2026-03-02 SecuritySnack - Idolized Crypto Scams Cybersecurity Reading List - Week of 2026-02-02 SecuritySnack: Phishing Interviews Pay to Lose: Dubious Online Gambling Games SecuritySnack: Repo The Repo - NPM Phishing Banker Trojan Targeting Indonesian and Vietnamese Android Users SecuritySnack: 18+E-Crime Cybersecurity Reading List - Week of 2026-01-05 Hunting for Malware Networks TrickBot the Unperturbed Silicon Valley Bank B2B2C Supply Chain Attack: Hotel’s Booking Accounts Compromised to Target Customers .GA Moves Away from FreeNom Cybersecurity Reading List - Week of 2025-03-04 Cybersecurity Reading List - Week of 2025-06-16 Cybersecurity Reading List - Week of 2025-05-19 "airdrop" Domain Bloom Cybersecurity Reading List - Week of 2025-04-21
Russian-based Prospero hosting & Squarespace as a registrar
DomainTools · 2026-01-05 · via DomainTools Investigations | SecuritySnacs

Western European targeted SMS campaigns that are phishing for credentials and banking information

We have been following a threat actor since at least November targeting western European countries with SMS campaigns, leading to the phishing of account credentials and banking information. Targets thus far include government benefits agencies, e-commerce giants, and video-on-demand services. This actor favors Russian-based Prospero hosting, and has now been detected using Squarespace as a registrar.


This actor often uses phrases like ‘facturacion’ (which translates into ‘billing’ or ‘invoice in several European languages) as well as ‘service,’ moncompte (my account), ‘suscripcion,’ and similar generic terms combined with specific brands or agencies to lure targets in for account takeover or bank fraud. Previously targeted countries include Norway, Sweden, Finland, and Austria; the Squarespace-registered batch appears to be targeting Germany, France, and Spain as well.


Recent domain examples below:
suscripcionfacturacion[.]com
facturacion-suscripcionvod[.]com
retrasofacturacion[.]com
facturacion-retraso[.]com
connect-accnfix[.]com
navgov-hu[.]com
ntflx-serviceup[.]com
ntlx-accuntmanage[.]com
serviceup-ntlx[.]com
ups-myserviceup[.]com


We advise network administrators consider blocking Prospero’s IPspace in its entirety and allow-listing elements on a case-by-case basis, if possible.


End-users should be wary of SMS-related banking alerts, and only input their banking credentials into known or verified websites and application. We advise users to never download banking applications from third-party app stores, and to always navigate to their bank’s website manually in order to avoid unknowingly entering credentials into cloned or fraudulent banking websites.

Visualization of 49 likely associated domains first seen or newly active from 2024-06-01 forward utilizing Squarespace registration and Prospero hosting, also showing commonalities among server type and risk score.

Cybersecurity Reading List - Week of 2026-06-01

Commentary followed by links to cybersecurity articles and resources that caught our interest internally.

SecuritySnack - Hijacking Corporate Sessions

A sophisticated AiTM phishing kit bypassing traditional MFA to steal Microsoft 365 session cookies. Get the full breakdown and IOCs.

Cybersecurity Reading List - Week of 2026-05-04

Systems thinking, biolistics, and the danger of mop-up science in infosec — plus this month's reading on ransomware, RPKI exploits, cPanel, and LLM pollution.