EfficientIP researchers flagged several AliExpress phishing domains before registration, uncovering a campaign that uses fake browser extensions to steal credentials.
Threat actors are combining social engineering with malicious OAuth applications to bypass password-based security and access sensitive Google Workspace data.

