New Phishing Campaign Targets US Government Organizations
ID: e7eb0d39-6cbf-520a-9f78-cff858a692da
STIX ID: report--e7eb0d39-6cbf-520a-9f78-cff858a692da
Feed Name: securityonline.info
Researchers observed an active Tycoon 2FA phishing campaign that targets US government email addresses (338 organizations) using compromised Amazon SES, obfuscated redirect chains, and fake Microsoft/Teams login pages. The attackers host a targeted email list on Cloudflare Pages and use multiple domains (for example MSOFT_DOCUSIGN_VERIFICATION_SECURED-DOC_OFFICE.zatrdg.com, donostain.com, vereares.ru) and legitimate services for hosting assets; credentials are harvested via encrypted POSTs. ANY.RUN sandbox analysis reproduces the full chain and confirms active credential-harvesting behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
