Cloud-Hosted Trap: Phishers Use Vercel & Telegram to Bypass Filters
ID: 28177b65-570a-5907-804e-c451e17c3d42
STIX ID: report--28177b65-570a-5907-804e-c451e17c3d42
Feed Name: securityonline.info
X-Labs describes a multi-stage phishing campaign that delivers a first PDF via email (clean of malicious links), which links to a second PDF hosted on legitimate cloud infrastructure and ultimately redirects victims to a fake Dropbox login page; harvested credentials and system/location data are exfiltrated via a Telegram bot. The campaign highlights evasion techniques—using trusted cloud services and clean-looking emails—to bypass reputation- and link-based defenses and steal user credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
