logo

Phishing campaigns use 'Employee Benefits' lure to intercept Microsoft and Okta logins

ID: 6e952900-e9d7-5f7a-b678-9377b2f46529

STIX ID: report--6e952900-e9d7-5f7a-b678-9377b2f46529

Feed Name: Threat Intelligence | Blog | Okta

Threat Score
70/100

Date Published: 2025-10-20

Date Updated: 2026-07-16

...
...

This report outlines the O-UNC-037 phishing campaign that uses fake Microsoft sign-in pages and Okta-targeting redirects—hosted across multiple domains and Cloudflare Workers—to steal credentials and session tokens via AitM techniques. The analysis identifies a configurable phishing kit/PhaaS, a Base64-encoded gatekeeper parameter, and provides numerous domains and URL paths as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.