The images in this article were generated with artificial intelligence. How we publish
Cybersecurity researchers have drawn up an increasingly refined operation of scams for users in the Middle East and North Africa, where attackers combine localized social engineering with abuse of legitimate browser features to extract money without installing traditional malware. The technique takes advantage of fraudulent accounts on social networks that supplant politicians, telecommunications companies and trusted organizations, and uses link in bio services as an intermediate layer before taking the victim to pages designed to obtain permits or force premium rate consumption.
A key technical aspect that analysts have identified is the abuse of web push notifications: malicious pages induce the user to press "Allow" to continue, and thus subscribe the browser to a notification system using VAPID keys. The re-use of the same VAPID key among different campaigns indicates a shared infrastructure behind fraud, which makes it easier for operators to scale and monetize multiple scams with the same technical components.

In addition to the use of notifications, attackers use history manipulation and tab-under techniques to keep the victim within their ecosystem, inflate advertising prints and redirect traffic to distribution systems that decide in real time whether to show premium SMS fraud, special pricing calls, investment scams or other traps. The model reveals that today fraud works more as a sophisticated marketing chain than as a classic technical attack..
The recent disarticulation of a commercial platform of physical-as- a- service showed that these operations can be "turnkey": anyone with access to the service can launch campaigns that combine supplanting, landing pages in legitimate services and monetization infrastructure. Although coordinated police actions represent progress, the underlying economy - PhaaS, notification networks and TDS - will continue to feed new campaigns if no action is taken on the technical and civil links.
For the common user, the good news is that many of these techniques exploit interactive decisions and permissions that we can control. Before granting notification permits or pressing promising links on social networks, it is appropriate to verify the final URL, distrust of too generous offers and remember that legitimate companies do not ask for such permits to "activate" promotions. Google maintains a practical guide to managing and revoking notifications permissions in Chrome that is useful for users: https: / / support.google.com / chrome / ansher / 3220216.
If you have already received unwanted notifications or suspicious charges, act quickly: revoke permissions in the browser and system settings, consult your mobile operator on SMS charges or premium calls and file a complaint to the platform where the fraudulent account appeared. To better understand tactics and mitigation against phishing in general, the US Cyber Security and Infrastructure Agency. UU offers useful guidelines: https: / / www.cisa.gov / uscert / ncas / tips.

Organizations also have clear responsibilities: link aggregation services, social networks and notification providers should strengthen controls to detect landing misleading pages housed in their domains, veto VAPID keys associated with recurrent abuse and improve the detection of redirection and assembly patterns of TDS. The security departments of telecommunications providers and public entities should monitor attempts at supplanting and quickly communicate to their customers how to distinguish official communications.
On a technical level, defending itself requires combining traditional measures and new best practices: blocking invasive scripts, using anti-phishing extensions, limiting permissions to what is strictly necessary, implementing block lists for malicious domains and enriching telemetry with suspicious web reporting indicators (e.g. VAPID footprint). Early detection and collaboration between platforms are essential to ensure that these monetization chains are not kept operational.
The central lesson is that modern fraud tends to hide behind legitimate technologies and flows that seem normal for the user. Combating it requires both public education and technical pressure on tools that allow abuse. To deepen how researchers and private companies operate against these threats, the work of specialized firms such as Group-IB documents cases and techniques; its website publishes reports and analyses that can serve as a reference for professionals: https: / / www.group-ib.com.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...