logo

HostPapa abuse treasure trove discovered in GoDaddy email threat hunt · Blog · Sublime Security

ID: 4e058dcd-7a38-5f4a-b0f7-10673da0b5e6

STIX ID: report--4e058dcd-7a38-5f4a-b0f7-10673da0b5e6

Feed Name: Sublime Security Blog

Threat Score
60/100

Date Published: 2026-01-15

Date Updated: 2026-05-01

...
...

This Attack Spotlight analyzes a set of phishing campaigns observed abusing hosting providers (HostPapa, GoDaddy) and cloud services to deliver credential-phishing (including AITM), callback scams, financial/social-engineering fraud, and malicious SVG attachments with obfuscated JavaScript; it highlights specific TTPs (copy/paste URL obfuscation, double extensions, DNA-sequence JS encoding), detection signals (SPF/DMARC failures, self-sender patterns), and example IOCs used to demonstrate detection and prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.