AITM phishing with Russian infrastructure and detection evasion from a lapsed domain · Blog · Sublime Security
ID: 74a2f5f4-57f1-51e7-9480-595a44997472
STIX ID: report--74a2f5f4-57f1-51e7-9480-595a44997472
Feed Name: Sublime Security Blog
Sublime Threat Research analyzes a targeted credential-phishing campaign that used a reclaimed legitimate law firm domain to send Microsoft Teams-style meeting invites linking to a sophisticated, multi-stage phishing infrastructure. The chain includes a gate page performing bot and domain checks, custom email encoding/decoding, large obfuscated JavaScript modules (with WebSocket and WebAssembly usage) for fingerprinting and control, and a final adversary-in-the-middle Office 365 login page to harvest credentials; the report includes IOCs and detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
