Abusive Bulletproof Hosting Networks Fuel Global Phishing Campaigns
ID: 96fa076d-227f-5403-8558-f3bae26c6c9e
STIX ID: report--96fa076d-227f-5403-8558-f3bae26c6c9e
Feed Name: securityonline.info
Researchers report a large, multi-region phishing campaign distributing obfuscated JavaScript implants and using abusive, bulletproof hosting providers (GHOSTYNETWORKS and OMEGATECH/Virtualine) to host spam and command infrastructure; victims include financial and energy organizations across several countries. The report also documents overlap with other criminal operators (TeamPCP) and a supply-chain compromise of the PyPI LiteLLM package that delivered credential-stealing code, and it recommends blocking known rogue AS prefixes, enforcing application controls, and tightening email gateway protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
