logo

New Phishing Attack Leverages Popular Brands to Harvest Login Credentials

ID: 258d6d8e-af59-5f4a-8fc3-361f5830c4f2

STIX ID: report--258d6d8e-af59-5f4a-8fc3-361f5830c4f2

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-11-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A sophisticated phishing campaign is targeting organizations in the Czech Republic, Slovakia, Hungary, and Germany across industries (agriculture, automotive, construction, education) by sending RFC-compliant HTML attachments that impersonate brands (Microsoft 365, Adobe, WeTransfer, FedEx, DHL) to harvest credentials and exfiltrate them directly to attacker-controlled Telegram bots; samples use AES-based obfuscation, anti-analysis measures (keyboard and context-menu blocking), and POSTs to api.telegram.org with hardcoded tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.