RingSafe Threat Bulletin — Tracker ID RST-XXXX-XXXX (illustrative) — 22 May 2026
Campaign profile
MorphLure (scenario actor) is a financially motivated cluster operating since at least November 2025, but its Indian-fintech focus is new. The actor uses ChatGPT-class LLMs to generate (a) hyper-realistic spear-phishing emails referencing the target’s actual recent calendar entries scraped from leaked Calendly metadata, (b) lookalike domains using IDN homoglyphs registered through Cloudflare-fronted hosting, and (c) 8-12 second voice deepfakes used in follow-up vishing calls.
Observed kill chain
- Recon — LinkedIn scraping of finance, treasury, compliance roles at Indian PA-PGs, neobanks, lending NBFCs.
- Initial access — spear-phish email containing a OneDrive lookalike link that delivers a stub loader signed with a recently-stolen Authenticode certificate.
- Credential harvest — Microsoft 365 lookalike login page that proxies the real auth flow (Evilginx2 variant) and captures session cookies post-MFA.
- Pivot — deepfake voice call to a junior finance staffer impersonating the CFO, requesting urgent wire transfer override.
RingSafe analysis
This is the cleanest example we have seen of an AI-native fraud kit being operationalised against the Indian BFSI surface. Two things matter: the actor has solved the “uncanny valley” voice problem that defeated earlier deepfake fraud, and they have built tradecraft around stealing Authenticode certs, which means traditional code-signing trust assumptions in your EDR policy now create a blind spot.
Detection signals
- Outbound DNS to
*.workers.devsubdomains containing Devanagari or Cyrillic homoglyphs of your corporate domain. - Microsoft Entra ID sign-in from a new device immediately followed by an OAuth consent grant to an unknown enterprise app.
- Authenticode-signed executables in
%APPDATA%LocalTempfrom publishers not in your signed-binary inventory.
What CISOs should do this week
- Add a verbal-callback policy on all wire transfers above ₹5 lakh, using a fresh phone number from HRMS — not the number on the requestor’s email signature.
- Enable Microsoft Defender for Cloud Apps “anomalous OAuth grant” policy if not already on.
- Brief the C-suite that their public conference talks are now training data for deepfake voices; restrict high-fidelity audio output.
Get a free attack-surface review
We check what an attacker would see about your business — leaked credentials, exposed services, dark-web mentions. 30 minutes, no obligation.