Callback phishing via invoice abuse and distribution list relays · Blog · Sublime Security
ID: 80b7ef43-0c9f-5ec5-8cf3-6f62c80c6299
STIX ID: report--80b7ef43-0c9f-5ec5-8cf3-6f62c80c6299
Feed Name: Sublime Security Blog
**Executive Summary:** This report describes a series of callback phishing campaigns where attackers create or compromise service accounts and use automated distribution lists to redirect legitimate-looking invoices (containing malicious phone numbers) to large numbers of targets while preserving the original sender, enabling scalable social-engineering attacks across Microsoft 365, PayPal and other services; Sublime outlines the attack steps, observed variants, detection signals, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
