Analysis of a JavaScript-based Phishing Campaign…
ID: 5f2b66ce-b52b-5a0b-8daf-37050a00cb98
STIX ID: report--5f2b66ce-b52b-5a0b-8daf-37050a00cb98
Feed Name: Binary Defense Blog
ARC Labs discovered a targeted credential-harvesting phishing campaign that uses PDF lures (QR codes), HTM attachments with obfuscated JavaScript and HTML smuggling, and CryptoJS-encrypted payloads to redirect victims through a multi-stage chain culminating in a fake Microsoft 365 login page; the report includes forensic analysis, observed redirection/decoding techniques, sandbox behavior (Cloudflare CAPTCHA and media-player lure), and a list of IoCs and a decoding utility for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
