logo

New Phishing Campaign Targets US Government Organizations

ID: e7eb0d39-6cbf-520a-9f78-cff858a692da

STIX ID: report--e7eb0d39-6cbf-520a-9f78-cff858a692da

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-08-22

Date Updated: 2026-04-22

Author: do son

...
...

Researchers observed an active Tycoon 2FA phishing campaign that targets US government email addresses (338 organizations) using compromised Amazon SES, obfuscated redirect chains, and fake Microsoft/Teams login pages. The attackers host a targeted email list on Cloudflare Pages and use multiple domains (for example MSOFT_DOCUSIGN_VERIFICATION_SECURED-DOC_OFFICE.zatrdg.com, donostain.com, vereares.ru) and legitimate services for hosting assets; credentials are harvested via encrypted POSTs. ANY.RUN sandbox analysis reproduces the full chain and confirms active credential-harvesting behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.