CSRF Research
Long-form investigative reports and original research on scams, vulnerabilities, and emerging threats — so you know what's out there and how to stay protected.
Latest
· Higor Silva
A convincing Nike job-site clone used a fake Facebook sign-in to target people looking for work.
Read the full report
All investigations
![It Looked Like Zillow. It Wasn't: Inside the zillowofficial[.]com Investment Scam](/investigations/zillowofficial/figure-7.png)
· Higor Silva
A passive OSINT investigation found that zillowofficial[.]com impersonated Zillow while presenting an investment-style platform and sharing a technical structure with similar domains.

· Faisal Hossain
A fake Government of Canada health-card email hid its scam page behind a fake security check, sending scanners and researchers to the real canada.ca.

· Narek Grigoryan
A T-Pot honeypot logged three Indonesian IP addresses scanning port 445 roughly 80,000 times; OSINT review found residential-proxy signals and exposed MikroTik infrastructure.

· Cybersecurity Reach Foundation
A report on a Shai-Hulud npm worm variant that targeted the TanStack ecosystem, harvested credentials, spread through developer environments, and planted destructive persistence.

· Seva Karonis
A review of OpenClaw's autonomous capabilities, local-machine access, reported issues, prompt-injection exposure, and safer deployment practices.
· Seva Karonis
A beginner-friendly guide to adopting agentic AI responsibly, including safe use, onboarding, permission boundaries, and tool evaluation.
· Cybersecurity Reach Foundation
A practical six-step OPSEC guide for investigators, researchers, and anyone who needs to reduce exposure while working online.

· Cybersecurity Reach Foundation
Messages sent through real Meetup accounts used a look-alike link and a fake security screen to lead event organizers to a page asking for bank and card details.
![ALERT: SpiderFoot Scam Resurfaced on spiderrfoot[.]com](/images/investigations/spiderfoot-screenshot.png)
· Cybersecurity Reach Foundation
A deceptive SpiderFoot distribution scheme resurfaced on spiderrfoot[.]com, showing how users can be misled when an open-source project has no official website.
![Rixav[.]sbs: A Crypto Wallet Phishing Site](/images/evidence/ev-1775096407945.png)
· Pammi Balani
rixav[.]sbs impersonates a wallet recovery service to trick users into entering their seed phrases and private keys. This report documents how the scam works, what the site does with your credentials, and why any wallet that touched it should be considered compromised.

· Tenzin Phuntsok
This investigation analyzes evofince[.]com, a cryptocurrency trading platform that presents itself as a high-volume digital asset exchange. Despite claims of regulatory licensing and years of operational history, domain records show the website was only registered in January 2026.

· Matthew Sweet
A website claiming to be a legitimate credit union appears to be part of a template-based financial scam network designed to collect personal information and solicit fraudulent loan payments.

· Pammi Balani
An unofficial website appearing in search results for the SpiderFoot OSINT tool may be misleading users into downloading software through untrusted channels. Despite the site itself stating it is not affiliated with the official project, search engine AI summaries identify it as the legitimate source