Method of infection: Water-holing
OSIRIS used a Social Engineering method called “water holing” to attack German IP addresses.
How does water holing attack work?
- The victim enters the infected website.
- The website checks if the target IP is German.
- If it’s a German IP – few evasion techniques are used to bypass EDR
- And then the virus connects to its command server through the Darknet
Save Your Company from Social Engineering Attacks Like that
Register and Get your Personalized Free Exposure Report NOW,
And see where your Company is Exposed to Hackers
Recently Posted on AUMINT.io Blog
How One Passenger Lost $17,000 to a United Airlines Scam – And What It Teaches Every Business About Fraud Prevention
✈️ $17,000 Gone Overnight – The United Airlines Scam Every Leader Must Understand
😱 A United Airlines passenger thought they were fixing a booking issue – instead, they lost $17,000 in hours.
🔎 Cybercriminals cloned support channels so well that the victim never realized they weren’t speaking with the real airline.
💡 Here’s the shocking part: the same tactic is already being used against employees, vendors, and executives. If one individual can be tricked so easily, imagine the risks inside an organization handling millions in transactions daily.
🚨 Attackers aren’t just sending clumsy phishing emails anymore. They use urgency, authority, and brand familiarity to manipulate human decisions. This isn’t a “tech” problem – it’s a human factor problem.
📊 For mid-market firms, one fraudulent transfer can create devastating financial and reputational damage. Prevention is no longer optional.
🔐 That’s where recurring simulation-driven training becomes critical. Employees need to recognize and resist these manipulations before real losses occur.
👉 AUMINT.io’s Trident platform equips businesses with ongoing, real-world attack simulations tailored to evolving threats.
💬 Are your teams ready for this type of attack? Or would they trust the fake “support line” too?
📅 Book your intro session here
and learn how to protect your organization before the next scam hits.
#CISO #CEO #CFO #FraudPrevention #CyberSecurity #AwarenessTraining #RiskManagement