Fake Invitation Phishing Campaign Steals Credentials From U.S. Organizations
ID: 7e30875d-1e25-550a-9e58-5548eb28ad79
STIX ID: report--7e30875d-1e25-550a-9e58-5548eb28ad79
Feed Name: GBHackers
Threat Score
**Phishing campaign leveraging fake event invitations**: A large-scale, ongoing phishing operation uses event-themed lures and a reusable framework to harvest credentials, intercept OTPs, and silently deliver remote monitoring/management tools (e.g., ScreenConnect, ConnectWise, Datto RMM) to establish persistent access; ANY.RUN analysts observed ~160 suspicious links and ~80 phishing domains and provided URL patterns and request-chain IOCs to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
