logo

Analysis of a JavaScript-based Phishing Campaign…

ID: 5f2b66ce-b52b-5a0b-8daf-37050a00cb98

STIX ID: report--5f2b66ce-b52b-5a0b-8daf-37050a00cb98

Feed Name: Binary Defense Blog

Threat Score
60/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

ARC Labs discovered a targeted credential-harvesting phishing campaign that uses PDF lures (QR codes), HTM attachments with obfuscated JavaScript and HTML smuggling, and CryptoJS-encrypted payloads to redirect victims through a multi-stage chain culminating in a fake Microsoft 365 login page; the report includes forensic analysis, observed redirection/decoding techniques, sandbox behavior (Cloudflare CAPTCHA and media-player lure), and a list of IoCs and a decoding utility for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.