Phishing campaign leading to Azure account takeover (Campaign)
ID: 9f690a04-cf17-5897-a44c-60cca999bc94
STIX ID: report--9f690a04-cf17-5897-a44c-60cca999bc94
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-12-18
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Unit 42 discovered a widespread phishing campaign (June–September 2024) targeting ~20,000 users in European automotive, chemical, and industrial sectors. The adversaries used HubSpot free-form pages and malicious DocuSign-like PDFs to harvest credentials, with the end goal of taking over Microsoft Azure accounts (credential theft, password resets, and MFA enrollment). HubSpot and DocuSign were confirmed not compromised; the campaign remained active as of September 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
