Criminals can now rent ready-made phishing kits that put up pixel-perfect fake login pages for apps like TikTok, Gmail, Apple and Amazon in about ten minutes, with a built-in AI to write the scam texts and emails that point to them. The twist: when you sign in, the page can also grab the session cookie that keeps you logged in, so they can walk straight into your account, 2FA code or not. Full write-up from Malwarebytes Labs.
The move
Never sign in through a link in a message — open the real app or a saved bookmark instead, and if you ever do enter details after a dodgy link, change your password and sign out of all sessions straight away.
Practise it: Would You Click? →
Seen via Malwarebytes Labs