Beware Of Malicious SharePoint Notifications Delivering Xloader Malware
ID: b9aa0935-ad84-5628-a2a1-1e472423a7ba
STIX ID: report--b9aa0935-ad84-5628-a2a1-1e472423a7ba
Feed Name: cybersecurityNews.com
A sophisticated phishing campaign impersonating Microsoft SharePoint delivers the Xloader (Formbook) infostealer by redirecting victims to externally hosted ZIP files containing disguised executables; the attack chain uses obfuscation, AutoIT scripts, shellcode and process-hijacking and leverages "living-off-trusted-sites" tactics to evade detection. Sublime Security flagged indicators such as brand impersonation, malicious redirect URLs, and SPF failures; recommended mitigations include email verification, URL inspection, MFA, user training, and advanced email/endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
