Hackers Targeting HubSpot Users in Targeted Phishing Attack
ID: af98d4ef-73dc-5163-83a2-2cf31c0940c1
STIX ID: report--af98d4ef-73dc-5163-83a2-2cf31c0940c1
Feed Name: cybersecurityNews.com
An active phishing campaign targets HubSpot users by sending convincing business emails (distributed at scale via MailChimp) that redirect victims from compromised websites to a fake HubSpot login hosted on Proton66 bulletproof infrastructure (ASN AS198953, IP 193.143.1.220). The attackers capture credentials via a login.php endpoint, leverage a Plesk-managed VPS with exposed mail services to rotate pages and manage compromised accounts, and use evasive tactics like embedding malicious URLs in the sender display name to bypass email security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
