Intel Drops #4
ID: 5a7ff17c-3ee2-532f-badc-23c190e8e888
STIX ID: report--5a7ff17c-3ee2-532f-badc-23c190e8e888
Feed Name: IntelInsights (Substack)
Threat Score
An ongoing phishing campaign leverages Cloudflare pages.dev infrastructure and CAPTCHA challenges to host Microsoft-themed credential-harvesting pages, using invoice/bid/signature email lures that redirect to spoofed OpenGov sites; analysis suggests a Rockstar2FA phishing kit, and the report shares numerous implicated domains (IoCs) while requesting further community intelligence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
