logo

Attackers Target Crypto Wallets Using Codeless Webflow Phishing Pages

ID: 4f2d3ade-3532-5ffe-8a39-80242e8c1808

STIX ID: report--4f2d3ade-3532-5ffe-8a39-80242e8c1808

Feed Name: Netskope Threat Labs

Threat Score
65/100

Date Published: 2024-10-23

Date Updated: 2026-04-28

Author: Jan Michael Alcantara

...
...

Netskope Threat Labs observed a surge in phishing campaigns (10x increase in traffic between April and September 2024) abusing Webflow to host or redirect to codeless phishing pages targeting crypto wallets (Coinbase, MetaMask, Phantom, Trezor, Bitbuy) and corporate webmail/Microsoft365 credentials; attackers use full-page screenshots and Webflow form/link blocks to harvest credentials and secret recovery phrases from victims, affecting over 120 organizations worldwide, and the report includes IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.