Targeted Large-Scale Campaign Attacking U.S. Organizations with Fake Event Invitations
ID: ee2f5f97-7d40-50ab-8a10-dacec96c512d
STIX ID: report--ee2f5f97-7d40-50ab-8a10-dacec96c512d
Feed Name: cybersecurityNews.com
A large-scale phishing campaign targets U.S. organizations in high-value sectors using fake event invitations and AI-assisted phishing pages to capture credentials and intercept OTPs, then quietly installs legitimate RMM tools (ScreenConnect, ITarian, Datto RMM) to establish persistent access; defenders are advised to watch for unauthorized RMM installations, suspicious outbound connections, CAPTCHA-based redirect chains, and predictable web request patterns such as /favicon.ico → /blocked.html and fixed resource paths like /Image/*.png.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
