All that JavaScript for… spear phishing?
ID: 34e225c7-4e15-53ac-96c2-6f459f970aeb
STIX ID: report--34e225c7-4e15-53ac-96c2-6f459f970aeb
Feed Name: NVISO Labs
Threat Score
This report analyzes a targeted spear-phishing campaign that uses HTML smuggling (obfuscated JavaScript with binary/hex arrays, base64 blobs, and AES-encrypted payloads) to deliver a chained payload which ultimately loads an iframe pointing to attacker-controlled domains that present a Microsoft Office 365 login page and exfiltrate credentials; the write-up includes multiple sample hashes, domains/URIs, observed AES keys, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
