260 Domains Hosting 5,000 Malicious PDFs to Steal Credit Card Data
ID: dcb44f54-d032-5fa7-a03f-2f5c4c83ff30
STIX ID: report--dcb44f54-d032-5fa7-a03f-2f5c4c83ff30
Feed Name: GBHackers
Netskope Threat Labs uncovered a global SEO-poisoning campaign distributing roughly 5,000 malicious PDFs across ~260 domains that embed fake CAPTCHA images to redirect victims to phishing pages (for payment and credential theft) and, in ~8% of cases, to PowerShell/MSHTA-based delivery of Lumma Stealer; the campaign has affected over 1,150 organizations and ~7,000 users across technology, financial services, and manufacturing, and abuses reputable CDNs and document repositories to evade detection, prompting recommendations for advanced URL filtering, PowerShell restrictions, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
