New Phishing Attack Leverages Popular Brands to Harvest Login Credentials
ID: 258d6d8e-af59-5f4a-8fc3-361f5830c4f2
STIX ID: report--258d6d8e-af59-5f4a-8fc3-361f5830c4f2
Feed Name: cybersecurityNews.com
A sophisticated phishing campaign is targeting organizations in the Czech Republic, Slovakia, Hungary, and Germany across industries (agriculture, automotive, construction, education) by sending RFC-compliant HTML attachments that impersonate brands (Microsoft 365, Adobe, WeTransfer, FedEx, DHL) to harvest credentials and exfiltrate them directly to attacker-controlled Telegram bots; samples use AES-based obfuscation, anti-analysis measures (keyboard and context-menu blocking), and POSTs to api.telegram.org with hardcoded tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
