5 Major Phishing Campaigns in March 2024
ID: 3f33298f-324b-5dc2-a2d7-c3559368c172
STIX ID: report--3f33298f-324b-5dc2-a2d7-c3559368c172
Feed Name: GBHackers
The report outlines five noteworthy March phishing campaigns that employed diverse and evolving techniques to steal credentials and deliver RATs: an SMB-based NTLM capture campaign (attributed to TA577), Cloudflare Workers phishing pages exfiltrating credentials to a Telegram bot, LATAM-targeted PDF→VBS→PowerShell chains dropping NjRAT/AsyncRAT/Remcos, JAR-based infections pulling STRRAT from GitHub/AWS, and a TikTok→Google AMP→Cloudflare redirect chain hosting obfuscated phishing forms — demonstrating active credential theft and malware distribution using legitimate cloud services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
