logo

Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links

ID: c6c215bd-e350-5aaa-8012-e31e08ea4215

STIX ID: report--c6c215bd-e350-5aaa-8012-e31e08ea4215

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Guru Baran

...
...

This report details a sophisticated supply-chain phishing campaign (active since Dec 2025) where attackers hijacked legitimate enterprise email threads via a compromised contractor account to deliver EvilProxy-based phishing pages that bypass bot protections (Cloudflare Turnstile) and exfiltrate credentials and session tokens; the campaign primarily targets Middle Eastern finance and energy firms and includes multiple IOCs and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.