Kratos phishing attack hidden in business term encoding and sophisticated obfuscation · Blog · Sublime Security
ID: 8a55c4c2-cde4-5efa-b9dd-b31bfee21771
STIX ID: report--8a55c4c2-cde4-5efa-b9dd-b31bfee21771
Feed Name: Sublime Security Blog
This report details a credential phishing campaign that delivered an SVG attachment disguised as an HTML file; the SVG contained an invisible “business analytics” dashboard and a data-analytics attribute holding a payload encoded via a 64-term business vocabulary. The attackers used a four-stage de-obfuscation chain (term-pair decoding, 8-byte block reversal, byte-offset subtraction, and XOR with a campaign-specific composite key), randomized identifiers, delayed execution, and dynamic string construction to evade detection and redirect victims to credential-harvesting pages pre-filled with the recipient’s email.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
