Callback phishing with online appointment abuse and distribution lists · Blog · Sublime Security
ID: 58afe049-31eb-5404-82e4-8e2c95c5375c
STIX ID: report--58afe049-31eb-5404-82e4-8e2c95c5375c
Feed Name: Sublime Security Blog
Attack Spotlight: A callback-phishing campaign used a bank's online "Request a Meeting" form and distribution-list relays to send legitimate-looking autogenerated meeting confirmations containing urgent financial language and repeated attacker-controlled phone numbers, leveraging legitimate domains to evade authentication; Sublime detected and blocked these messages using signals like mismatched context, multiple phone numbers, urgent language, commonly abused brands, and suspicious return paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
