logo

AITM phishing with Russian infrastructure and detection evasion from a lapsed domain · Blog · Sublime Security

ID: 74a2f5f4-57f1-51e7-9480-595a44997472

STIX ID: report--74a2f5f4-57f1-51e7-9480-595a44997472

Feed Name: Sublime Security Blog

Threat Score
72/100

Date Published: 2026-01-08

Date Updated: 2026-05-01

...
...

Sublime Threat Research analyzes a targeted credential-phishing campaign that used a reclaimed legitimate law firm domain to send Microsoft Teams-style meeting invites linking to a sophisticated, multi-stage phishing infrastructure. The chain includes a gate page performing bot and domain checks, custom email encoding/decoding, large obfuscated JavaScript modules (with WebSocket and WebAssembly usage) for fingerprinting and control, and a final adversary-in-the-middle Office 365 login page to harvest credentials; the report includes IOCs and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.