{"id":3644,"date":"2025-05-08T13:37:44","date_gmt":"2025-05-08T13:37:44","guid":{"rendered":"http:\/\/localhost\/?p=3644"},"modified":"2025-05-08T13:37:44","modified_gmt":"2025-05-08T13:37:44","slug":"cyber-criminals-impersonate-payroll-hr-and-benefits-platforms-to-steal-information-and-funds","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=3644","title":{"rendered":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds"},"content":{"rendered":"<h2>Security Update News<\/h2>\n<h3>Update Information<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Title<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Update ID<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">MALWAREBYTES:C4969F80FC21011210563A880B97CC62<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Type<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">malwarebytes<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Published<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-05-08T17:01:19<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Last Updated<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">2025-05-08T17:01:19<\/td>\n<\/tr>\n<\/table>\n<h3>Security Impact<\/h3>\n<table style=\"width:100%; border-collapse: collapse; margin-bottom: 20px;\">\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">CVSS Score<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\">0.0<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Severity<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd; color: #666666; font-weight: bold;\">NONE<\/td>\n<\/tr>\n<tr>\n<th style=\"text-align: left; padding: 8px; border: 1px solid #ddd; \">Attack Vector<\/th>\n<td style=\"padding: 8px; border: 1px solid #ddd;\"><\/td>\n<\/tr>\n<\/table>\n<h3>Affected CVEs<\/h3>\n<div style=\" padding: 15px; border: 1px solid #ddd; margin-bottom: 20px;\">\n<ul style=\"margin: 0; padding-left: 20px;\">\n<\/ul>\n<\/div>\n<h3>Update Details<\/h3>\n<div style=\"; padding: 15px; border-left: 4px solid #4CAF50; margin-bottom: 20px;\">\nThe relentless battle against online fraud is a constant evolution, a digital chase where security teams and malicious actors continually adapt. The increasing sophistication of attacks is blurring the lines between legitimate user behavior and impersonation attempts.<\/p>\n<p>The campaign we are exposing today is a reminder that even the most advanced security technologies do not dissuade threat actors. We discovered a new phishing kit targeting payroll and payment platforms that aims to not only steal victims&#8217; credentials but also to commit wire fraud.<\/p>\n<p>Our investigation began with a fraudulent search ad for Deel, a payroll and human resources company. Clicking on the ad sent employees and employers to a phishing website impersonating Deel.<\/p>\n<p>Beside stealing usernames, passwords and circumventing two factor authentication, we identified malicious code capable of performing additional nefarious actions unbeknownst to the victim. Using a fully authenticated web worker, this phishing kit is using a legitimate hosted web service called Pusher with the intent of manipulating sensitive profile data fields related to banking and payment information.<\/p>\n<p>While we were working this case, the FBI issued a public service announcement (PSA250424) warning people that cyber criminals are _using search engine advertisements to impersonate legitimate websites_ and _expanded to target payroll, unemployment programs, and health savings accounts with the goal of stealing money through fraudulent wire transactions or redirecting payments_.<\/p>\n<p>The Google ad was taken down quickly, and we have informed Deel and MessageBird (Pusher&#8217;s parent company) about the misuse of their respective platforms.<\/p>\n<p>## Search results ad targets Deel<\/p>\n<p>Deel is a US-based payroll and human resources company founded in 2019 Deel whose platform is designed to streamline the complexities of managing a global workforce, offering solutions for payroll, HR, compliance, and more.<\/p>\n<p>We first identified a malicious Google Search ad for Deel in mid April for the keywords &#8216;_deel login_ &#8216;. The top link is a sponsored search result, appearing just above the organic search result for Deel&#8217;s official website.<\/p>\n<p>The URL in the ad (_deel[.]za[.]com_) uses the .ZA.COM subdomain of .COM targeting South Africa, essentially an alternative to the .CO.ZA extension. That URL is used as a redirect only, allowing the threat actors to use cloaking in order to redirect clicks to decoy websites (white page) or phishing domains they can rotate.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_bb2686.png)<\/p>\n<p>## Phishing portal and 2FA<\/p>\n<p>The first phishing domain we saw was _login-deel[.]app_ but at the time we checked it did not resolve. Shortly thereafter, the same Google ad URL pointed to a new domain, _accuont-app-deel[.]cc_.<\/p>\n<p>The phishing page is a replica of Deel&#8217;s login page with one minor difference: _the Log in using Google_ and _Continue with QR code_ options are disabled, only leaving the user name and password fields for authentication.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_fe7aa6.png?w=1024)<\/p>\n<p>After entering their credentials, victims are social engineered by the crooks to type a security code that was sent to their email address. While two-factor authentication is a great added security feature, we can see that it can be rendered useless when victims authenticate into the wrong website.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_6fb280.png?w=1024)<\/p>\n<p>On the surface, this looks just like another phishing site, until you look deeper and discover more intriguing code.<\/p>\n<p>## Traffic analysis<\/p>\n<p>To better understand how this phishing kit works, we recorded a network capture showing the web requests sent and received. This allowed us to identify several interesting components that make this phishing campaign unique.<\/p>\n<p>Of particular interest are several JavaScript libraries, namely _pusher.min.js_ , _Worker.js_ and _kel.js_.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_f9ea30.png)<\/p>\n<p>The phishing kit uses anti-debugging techniques to prevent us from stepping through its code. This is a common practice to hide malicious intent and makes analysis more time consuming.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_dbf40b.png)<\/p>\n<p>## Scripts analysis<\/p>\n<p>Looking at the files that the anti-debugger is trying to conceal, we see that only one is human readable, while the other two are heavily obfuscated using _obfuscator.io_. The _pusher.min.js_ JavaScript file is a legitimate library from Pusher, a hosted web service that uses APIs, developer tools and libraries to manage connections between servers and clients using technologies like WebSockets.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_078bf2.png?w=696)<\/p>\n<p>There seems to be two different types of sessions, based on the functions named _createBankSession_ and _createCardSession_. When attempting to login into the phishing site, we see a session_type value of &#8220;bank&#8221; which belongs to the former function.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/05\/image.png)<\/p>\n<p>The _kel.js_ and Worker.js files are both used for authenticating the victim into the real Deel website while a web worker communicates with the threat actor&#8217;s infrastructure for processing the credentials and to receive the OTP code to get past two-factor authentication.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_c55395.png)<\/p>\n<p>WebSockets are a persistent communication protocol that allows for full-duplex communication between a user&#8217;s browser and a server. This means data can be pushed from the server to the client in real-time without the client having to constantly request it.<\/p>\n<p>Here&#8217;s an example of a WebSocket communication where the user provided the wrong login credentials:<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_bd7a5e.png)<\/p>\n<p>The conversation begins with a `pusher:connection_established` message, confirming a successful connection to the Pusher real-time service and providing a unique `socket_id` and an `activity_timeout` of 120 seconds.<\/p>\n<p>Next, a `pusher:subscribe` message shows the client requesting to listen for events on a specific channel identified by a unique session ID, indicating a desire to receive real-time updates for that session.<\/p>\n<p>The server then acknowledges this request with a `pusher_internal:subscription_succeeded` message for the same channel, confirming that the client is now successfully subscribed and will receive broadcasts.<\/p>\n<p>Finally, an `events` message is received on that session channel, carrying data indicating a &#8220;wrongLogin&#8221; event has occurred and instructing the client-side application to &#8220;Show&#8221; something, likely an error message to the user in real-time.<\/p>\n<p>## Additional targets<\/p>\n<p>This phishing kit is unique and can be tracked with the following characteristics:<\/p>\n<p>  * Obfuscator.io<br \/>  * Pusher WebSockets<br \/>  * _Worker.js_ library<br \/>  * _kel.js_ \/_otp.js_ \/_auth.js\/jquery.js_ library<\/p>\n<p>We identified several other targets, related to payroll, HR, billing, payment solutions and even commerce platform Shopify. The earliest use we could find goes back to July 2024, but it appears to have flown under the radar.<\/p>\n<p>**Justworks** : Payroll, benefits, HR, and compliance \u2014 all in one place.<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/04\/image_955656.png?w=1024)<\/p>\n<p>**Marqeta** : End to end credit and payment solutions integration into business processes<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/05\/image_ddd1e7.png)<\/p>\n<p>**Shopify** : Commerce platform<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/05\/image_7a4d9b.png)<\/p>\n<p>**OmniFlex** (Worldpay): online point of sale solution<\/p>\n<p>![](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/05\/image_23f2a7.png)<\/p>\n<p>## Conclusion<\/p>\n<p>The FBI&#8217;s PSA highlights several key measures businesses can adopt to protect users related to the following:<\/p>\n<p>  * Domain spoofing: Brand impersonation is a real problem that companies need to proactively lookout for.<br \/>  * Notifications: Victims need to be alerted in several different ways in a timely manner.<br \/>  * Education: Phishing is getting more sophisticated and users need to be aware of how to best protect themselves.<\/p>\n<p>In that same report, the FBI advises consumers to check the URL to make sure the site is authentic before clicking on an advertisement. This is usually a sound practice, but as we have documented it on this blog many times, URLs within ads can be spoofed also.<\/p>\n<p>Ultimately, the discovery of this phishing kit, with its advanced capability to interact with financial data, reinforces a critical message: online security is a shared responsibility. Users must exercise caution and critical thinking in their online interactions while enhancing their security with available tools; platforms must remain committed to detecting and preventing abuse.<\/p>\n<p>Browser extensions such as Malwarebytes Browser Guard will block ads but also the scams or malware sites associated with these schemes.<\/p>\n<p>* * *<\/p>\n<p>**We don &#8216;t just report on threats &#8211; we help safeguard your entire digital identity**<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using identity protection.<\/p>\n<p>## Indicators of Compromise<\/p>\n<p>Redirect<\/p>\n<p>    deel[.]za[.]com<\/p>\n<p>Phishing domains<\/p>\n<p>    login-deel[.]app  <br \/>    accuont-app-deel[.]cc  <br \/>    justvvokrs-login[.]cc  <br \/>    vye-starr[.]net  <br \/>    maqreta[.]com  <br \/>    ctelllo[.]com  <br \/>    angelistt[.]com  <br \/>    account[.]datedeath[.]com  <br \/>    account[.]turnkeycashsite[.]com  <br \/>    admin-shopffy[.]cc  <br \/>    biilll[.]com  <br \/>    app-parker[.]com  <br \/>    shluhify[.]com  <br \/>    login-biil[.]net  <br \/>    founderga[.]com  <br \/>    admin-shoopiffy[.]com  <br \/>    access-shupfify[.]com  <br \/>    virluaterminal[.]net<\/p>\n<p>Worker.js (SHA256)<\/p>\n<p>    56755aaba6da17a9f398c3659237d365c52d7d8f0af9ea9ccde82c11d5cf063f<\/p>\n<p>kel.js\/otp.js\/auth.js\/jquery.js (SHA256)<\/p>\n<p>    72864bd09c09fe95360eda8951c5ea190fbb3d3ff4424837edf55452db9b36fb  <br \/>    6fb006ecc8b74e9e90d954fa139606b44098fc3305b68dcdf18c5b71a7b5e80f  <br \/>    908a128f47b7f34417053952020d8bbdacf3aed1a1fcf4981359e6217b7317c9  <br \/>    5dadc559f2fb3cff1588b262deb551f96ff4f4fc05cd3b32f065f535570629c3  <br \/>    0ef66087d8f23caf2c32cc43db010ffe66a1cd5977000077eda3a3ffce5fa65f  <br \/>    95d008f7f6f6f5e3a8e0961480f0f7a213fa7884b824950fe9fb9e40d918a164  <br \/>    3e4e78a3e1c6a336b17d8aed01489ab09425b60a761ff86f46ab08bfcf421eac  <br \/>    a37463862628876cecfc4f55c712f79a150cdc6ae3cf2491a39cc66dadcf81eb  <br \/>    15606c5cd0e536512a574c508bd8a4707aace9e980ab4016ce84acabed0ad3be  <br \/>    81bcf866bd94d723e50ce791cea61b291e1f120f3fc084dc28cbe087b6602573  <br \/>    1665387c632391e26e1606269fb3c4ddbdf30300fa3e84977b5974597c116871  <br \/>    c56e277fd98fc2c28f85566d658e28a19759963c72a0f94f82630d6365e62c4f\n<\/div>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/cybercrime\/2025\/05\/cyber-criminals-impersonate-payroll-hr-and-benefits-platforms-to-steal-information-and-funds\" target=\"_blank\" style=\"display: inline-block; color: white; padding: 10px 20px; text-decoration: none; border-radius: 4px;\">View Advisory Details<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Update News Update Information Title Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds Update ID MALWAREBYTES:C4969F80FC21011210563A880B97CC62 Type malwarebytes Published&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,34,12,115,13,33,7,11,5],"class_list":["post-3644","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-cvss-00","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=3644\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem\" \/>\n<meta property=\"og:description\" content=\"Security Update News Update Information Title Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds Update ID MALWAREBYTES:C4969F80FC21011210563A880B97CC62 Type malwarebytes Published...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=3644\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-08T13:37:44+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds\",\"datePublished\":\"2025-05-08T13:37:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644\"},\"wordCount\":1716,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-0.0\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=3644#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644\",\"name\":\"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-05-08T13:37:44+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=3644\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=3644#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=3644","og_locale":"en_US","og_type":"article","og_title":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem","og_description":"Security Update News Update Information Title Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds Update ID MALWAREBYTES:C4969F80FC21011210563A880B97CC62 Type malwarebytes Published...","og_url":"https:\/\/zero.redgem.net\/?p=3644","og_site_name":"zero redgem","article_published_time":"2025-05-08T13:37:44+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=3644#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=3644"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds","datePublished":"2025-05-08T13:37:44+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=3644"},"wordCount":1716,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-0.0","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=3644#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=3644","url":"https:\/\/zero.redgem.net\/?p=3644","name":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-05-08T13:37:44+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=3644#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=3644"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=3644#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Cyber criminals impersonate payroll, HR and benefits platforms to steal information and funds"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/3644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3644"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/3644\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}