Attackers Target Crypto Wallets Using Codeless Webflow Phishing Pages
ID: 4f2d3ade-3532-5ffe-8a39-80242e8c1808
STIX ID: report--4f2d3ade-3532-5ffe-8a39-80242e8c1808
Feed Name: Netskope Threat Labs
Netskope Threat Labs observed a surge in phishing campaigns (10x increase in traffic between April and September 2024) abusing Webflow to host or redirect to codeless phishing pages targeting crypto wallets (Coinbase, MetaMask, Phantom, Trezor, Bitbuy) and corporate webmail/Microsoft365 credentials; attackers use full-page screenshots and Webflow form/link blocks to harvest credentials and secret recovery phrases from victims, affecting over 120 organizations worldwide, and the report includes IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
