Analysis of Phishing Kill Chain Identifies Emerging Technique That Exploits Trust in Your Collaboration Platforms
ID: 815b9487-f3c9-544a-8363-a25e37ea995e
STIX ID: report--815b9487-f3c9-544a-8363-a25e37ea995e
Feed Name: Cato Networks
Threat Score
This report analyzes an active phishing campaign that leverages compromised collaboration-platform accounts and legitimate web hosting to distribute credential-harvesting pages. It details the phishing kit structure, typical drop filenames (e.g., next.php, n.php), base64-encoded exfiltration URLs, example server responses ({"signal":"ok","msg":"InValid Credentials"}), and network/code attributes that defenders can use to detect and block the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
