logo

Tracking Crimson Kingsnake

ID: 9df2d49b-c5b2-599f-a65c-7f059d13a21e

STIX ID: report--9df2d49b-c5b2-599f-a65c-7f059d13a21e

Feed Name: KMsec blog

Threat Score
55/100

Date Published: 2023-01-06

Date Updated: 2026-04-19

...
...

This report documents the Crimson Kingsnake invoice‑fraud campaign: targeted spearphishing lures and follow-up thread hijacks using compromised Office365 accounts and typo‑squatted domains to deliver PDF invoices. The author used VirusTotal pivots to identify victim organizations, recurring metadata fingerprints (PDF author 'hpins'), domain lists, file hashes, and a LiveHunt YARA rule to track the campaign and surface IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.