Jobseekers exploited in fake recruiter phishing campaigns
ID: 31410945-940c-5a7d-b8be-1c1a3f25db88
STIX ID: report--31410945-940c-5a7d-b8be-1c1a3f25db88
Feed Name: Okta Threat Intelligence
Phishing actors are creating or hijacking email-marketing accounts to send large-scale phishing campaigns. One tracked cluster (143 domains) uses a Browser-in-the-Browser (BitB) technique to present fake Facebook login dialogs and capture credentials, hosts sites on services like Vercel and AWS, registers domains at registrar.eu, and uses a Telegram bot for credential exfiltration and site updates; Okta shared domains with Salesforce which suspended the associated accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
