logo

Analysis of Phishing Kill Chain Identifies Emerging Technique That Exploits Trust in Your Collaboration Platforms

ID: 815b9487-f3c9-544a-8363-a25e37ea995e

STIX ID: report--815b9487-f3c9-544a-8363-a25e37ea995e

Feed Name: Cato Networks

Threat Score
60/100

Date Published: 2022-01-25

Date Updated: 2026-07-23

Author: Zohar Buber

...
...

This report analyzes an active phishing campaign that leverages compromised collaboration-platform accounts and legitimate web hosting to distribute credential-harvesting pages. It details the phishing kit structure, typical drop filenames (e.g., next.php, n.php), base64-encoded exfiltration URLs, example server responses ({"signal":"ok","msg":"InValid Credentials"}), and network/code attributes that defenders can use to detect and block the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.