Phishing campaigns use 'Employee Benefits' lure to intercept Microsoft and Okta logins
ID: 6e952900-e9d7-5f7a-b678-9377b2f46529
STIX ID: report--6e952900-e9d7-5f7a-b678-9377b2f46529
Feed Name: Threat Intelligence | Blog | Okta
Threat Score
This report outlines the O-UNC-037 phishing campaign that uses fake Microsoft sign-in pages and Okta-targeting redirects—hosted across multiple domains and Cloudflare Workers—to steal credentials and session tokens via AitM techniques. The analysis identifies a configurable phishing kit/PhaaS, a Base64-encoded gatekeeper parameter, and provides numerous domains and URL paths as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
