logo

5 Major Phishing Campaigns in March 2024

ID: 3f33298f-324b-5dc2-a2d7-c3559368c172

STIX ID: report--3f33298f-324b-5dc2-a2d7-c3559368c172

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2024-04-02

Date Updated: 2026-04-22

Author: Cyber Writes

...
...

The report outlines five noteworthy March phishing campaigns that employed diverse and evolving techniques to steal credentials and deliver RATs: an SMB-based NTLM capture campaign (attributed to TA577), Cloudflare Workers phishing pages exfiltrating credentials to a Telegram bot, LATAM-targeted PDF→VBS→PowerShell chains dropping NjRAT/AsyncRAT/Remcos, JAR-based infections pulling STRRAT from GitHub/AWS, and a TikTok→Google AMP→Cloudflare redirect chain hosting obfuscated phishing forms — demonstrating active credential theft and malware distribution using legitimate cloud services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.