Phishing for Xfinity credentials with malicious Zoom Docs · Blog · Sublime Security
ID: 8468db82-0559-5046-92b8-99923d39044d
STIX ID: report--8468db82-0559-5046-92b8-99923d39044d
Feed Name: Sublime Security Blog
Threat Score
This Attack Spotlight describes a credential-phishing campaign where attackers impersonated Xfinity, used a Zoom Doc (docs.zoom.us) to host an Xfinity-branded landing page, and redirected victims to a separate phishing domain to harvest credentials; Sublime's AI (ASA) detected the attack using signals including brand impersonation, domain mismatch, urgent language, and intentional misspellings for filter evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
