Twitter link shortener (t.co) to hide an AITM credential phishing payload · Blog · Sublime Security
ID: 1eb5611f-1f91-561b-8bed-8d38cff02f0e
STIX ID: report--1eb5611f-1f91-561b-8bed-8d38cff02f0e
Feed Name: Sublime Security Blog
This Attack Spotlight details a Q1 2025 credential-phishing campaign that abused Living Off Trusted Sites (LOTS) — using X's t.co shortener to redirect victims to a Firebase-hosted Adversary-in-the-Middle (AITM) credential phishing page that impersonated DocuSign/ShareFile/Adobe/Microsoft to harvest Microsoft OAuth credentials; Sublime detected and blocked the attack and highlights detection signals like brand confusion, lookalike sender domain (edocs.com), link shortener use, and financial urgency.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
