Phishing Campaign Abuses Event Invitations To Target U.S. Firms
ID: 38257dd1-f4bd-5cef-b5bd-9278539a7102
STIX ID: report--38257dd1-f4bd-5cef-b5bd-9278539a7102
Feed Name: Cyber Press
This report details a widespread phishing campaign impersonating corporate event invitations to target U.S. organizations—particularly in banking, government, technology, and healthcare—combining credential harvesting and OTP interception with stealthy installation of legitimate RMM tools (ScreenConnect, ITarian, Datto RMM) to bypass MFA and obtain persistent remote access; the attack leverages CAPTCHA gating and AI-generated pages and leaves repeatable early-stage network patterns defenders can use to detect and stop the intrusion before credential theft occurs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
