Christmas Tycoon
ID: 1f3fd44d-484c-5c7c-a3bf-05dd3ff9e417
STIX ID: report--1f3fd44d-484c-5c7c-a3bf-05dd3ff9e417
Feed Name: IntelInsights (Substack)
Starting from a Cisco Secure Email–wrapped phishing URL that redirected to a Tycoon phishing kit credential-harvesting site, the report fingerprints the kit’s infrastructure (AI chatbot fallback, banner hashes, recurring HTML titles) to pivot across providers and TLDs, clustering campaigns and uncovering ~1,900 unique, recently active domains. It highlights automated, template-based landing pages (e.g., “Finquick,” “Desio Copilot,” “VoltGrid,” “Flowguide,” “TimberCraft”), redirection overlap, possible DGA usage, and open directories—indicating a high-volume, scalable phishing operation relying on cloud/CDN hosting and infrastructure reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
