Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links
ID: c6c215bd-e350-5aaa-8012-e31e08ea4215
STIX ID: report--c6c215bd-e350-5aaa-8012-e31e08ea4215
Feed Name: cybersecurityNews.com
Threat Score
This report details a sophisticated supply-chain phishing campaign (active since Dec 2025) where attackers hijacked legitimate enterprise email threads via a compromised contractor account to deliver EvilProxy-based phishing pages that bypass bot protections (Cloudflare Turnstile) and exfiltrate credentials and session tokens; the campaign primarily targets Middle Eastern finance and energy firms and includes multiple IOCs and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
