logo

All that JavaScript for… spear phishing?

ID: 34e225c7-4e15-53ac-96c2-6f459f970aeb

STIX ID: report--34e225c7-4e15-53ac-96c2-6f459f970aeb

Feed Name: NVISO Labs

Threat Score
55/100

Date Published: 2024-10-02

Date Updated: 2026-04-28

Author: Bart Parys

...
...

This report analyzes a targeted spear-phishing campaign that uses HTML smuggling (obfuscated JavaScript with binary/hex arrays, base64 blobs, and AES-encrypted payloads) to deliver a chained payload which ultimately loads an iframe pointing to attacker-controlled domains that present a Microsoft Office 365 login page and exfiltrate credentials; the write-up includes multiple sample hashes, domains/URIs, observed AES keys, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.