Credential Theft Campaign Uses Fake Invitations To Target U.S. Firms
ID: e0de894e-286a-54b5-a80b-09156f030a31
STIX ID: report--e0de894e-286a-54b5-a80b-09156f030a31
Feed Name: Cyber Press
**Executive Summary:** A large-scale phishing campaign is targeting U.S. organizations (education, banking, government, technology, healthcare) using fake event invitations that either harvest credentials and OTPs or silently deliver legitimate RMM tools (ScreenConnect, ITarian, Datto RMM, ConnectWise, LogMeIn Rescue) to establish remote access; researchers observed ~80 domains, characteristic URL/icon patterns, and a unique sequential resource request fingerprint useful for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
