Attackers Abuse HubSpot’s Free Form Builder to Craft Phishing Pages
ID: 76e50581-5180-595a-9b6a-0d20a2786331
STIX ID: report--76e50581-5180-595a-9b6a-0d20a2786331
Feed Name: KnowBe4 Blog
#### Executive summary: Palo Alto Networks Unit 42 identified a large-scale credential-harvesting phishing campaign targeting at least 20,000 users at European companies (automotive, chemical, industrial), using DocuSign-enabled PDFs and malicious HubSpot Free Form Builder links to steal credentials and take over Microsoft Azure accounts; attackers leveraged VPNs and bulletproof VPS hosting and reused infrastructure across operations, and HubSpot was not compromised during the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
