'LockBit of phishing' EvilProxy used in more than a million attacks every month
ID: 8fedd80c-737c-57c9-bf49-5304d04298be
STIX ID: report--8fedd80c-737c-57c9-bf49-5304d04298be
Feed Name: The Register (Security)
Threat Score
The report details active, large-scale phishing campaigns powered by the EvilProxy PhaaS reverse-proxy that dynamically proxies real login pages to harvest credentials, session cookies and MFA tokens while using Cloudflare and multi-stage redirects to evade automated detection; Proofpoint and Menlo observations show widespread use, high-volume detections, and adoption by known actors TA4903 and TA577 targeting high-value executives and organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
