logo

Twitter link shortener (t.co) to hide an AITM credential phishing payload · Blog · Sublime Security

ID: 1eb5611f-1f91-561b-8bed-8d38cff02f0e

STIX ID: report--1eb5611f-1f91-561b-8bed-8d38cff02f0e

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

This Attack Spotlight details a Q1 2025 credential-phishing campaign that abused Living Off Trusted Sites (LOTS) — using X's t.co shortener to redirect victims to a Firebase-hosted Adversary-in-the-Middle (AITM) credential phishing page that impersonated DocuSign/ShareFile/Adobe/Microsoft to harvest Microsoft OAuth credentials; Sublime detected and blocked the attack and highlights detection signals like brand confusion, lookalike sender domain (edocs.com), link shortener use, and financial urgency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.