Loading...
Threat Intelligence
We run an identity provider, so we get a close view of credential phishing, brand impersonation and the infrastructure behind them. When we analyse something, we publish it — including the parts that are inconvenient for us.
A reader objected that merely loading a web page cannot compromise a phone — you would have to download and run something. That was true in 2015. We walk through why opening the page is already the download, how a state-grade iOS exploit chain became commodity crimeware in six months, and why the same attack shows Android visitors nothing but a phishing form.
A user reported two SMS messages carrying a Binance verification code they never asked for, and a link on a genuinely authentic Binance domain. The link is real, the shortener is Binance's own, and the page at the end asks you for nothing at all. We decode the full chain and explain why the fake code is the cleverest part of the attack.
Abuse desks, registrars, CERTs and researchers: threat@uniauth.id. We answer, and we will share captured payloads and hashes on request.