New Phishing Attack Bypasses Using UUIDs Unique to Bypass Secure Email Gateways
ID: 662c38c9-e25c-5b69-ad64-eb15351e210c
STIX ID: report--662c38c9-e25c-5b69-ad64-eb15351e210c
Feed Name: cybersecurityNews.com
**Sophisticated UUID-driven phishing campaign leveraging dynamic DOM replacement:** A phishing operation uses randomly generated UUIDs and randomly selected bulk-generated domains embedded in HTML attachments or spoofed file-sharing platforms (OneDrive, SharePoint, DocuSign, Adobe Sign) to bypass Secure Email Gateways; the malicious script posts victim context to a server which returns branded login pages and replaces page content via DOM manipulation (no redirect) to harvest credentials, with Cofense reporting active use in early February 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
