New Phishing Attack Weaponizing Event Invitations to Steal Login Credentials
ID: 189906a6-c227-519e-834e-448a56850ceb
STIX ID: report--189906a6-c227-519e-834e-448a56850ceb
Feed Name: cybersecurityNews.com
### Executive Summary A widespread phishing campaign targets U.S. organizations (education, banking, government, technology, healthcare) using fake event invitations that pass a CAPTCHA and show polished pages to harvest credentials (including OTPs) or initiate downloads of legitimate remote management tools (ScreenConnect, ConnectWise, LogMeIn, etc.). Researchers observed roughly 160 suspicious links and ~80 phishing domains, with consistent URL/request patterns and shared endpoints (e.g., /blocked.html, /Image/*.png, /pass.php, /mlog.php). The report includes IOCs and a hunting query for earlier detection and advises sandbox analysis and shared infrastructure hunting to reduce risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
