Manufacturing Sector Is the Latest Target of Advanced Credential Harvesting Attacks
ID: 0cb6b0f7-3db7-52c1-a565-2efbf0738b45
STIX ID: report--0cb6b0f7-3db7-52c1-a565-2efbf0738b45
Feed Name: KnowBe4 Blog
A slow, targeted credential-harvesting phishing campaign has been observed targeting North American manufacturing organizations: attackers send emails with HTML attachments named like “Product List RFQ, NDA & Purchase Terms 2024.shtml” that spoof Microsoft 365 login pages to steal credentials. The campaign appears low-volume (about 15 companies over six months) but potentially sophisticated, using look-alike domains that lay dormant after registration and impersonations of legitimate suppliers to increase success.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
