Adventures in Phishing Email Analysis
ID: d1aceef7-1bf4-5c72-a205-b5bacdc9f3e8
STIX ID: report--d1aceef7-1bf4-5c72-a205-b5bacdc9f3e8
Feed Name: TrustedSec blog
Threat Score
This report analyzes a credential-harvesting phishing campaign that used Firebase-hosted fake OWA pages and embedded JavaScript keylogging to capture user credentials; investigators recovered an exposed file containing harvested credentials, confirmed Office 365 mailbox compromises for affected users, monitored ongoing campaign activity across multiple countries, and attempted responsible disclosure and takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
