Talking phish over turkey · Blog · Sublime Security
ID: 0dfac420-f159-56f2-88ee-33cc038ec982
STIX ID: report--0dfac420-f159-56f2-88ee-33cc038ec982
Feed Name: Sublime Security Blog
This blog-style threat intelligence note describes a series of year-end credential phishing campaigns that impersonate HR, benefits, and review communications (open enrollment, bonus notifications, annual certifications). It highlights common signals and TTPs—authoritative display names, brand impersonation, QR codes, suspicious attachments and document notifications, HTML attachments with obfuscated JavaScript that render fake login forms, and the abuse of legitimate services (e.g., DocuSign)—and encourages awareness and defensive behavior to reduce credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
