Phishing Deep Dive: EU-Affiliated Survey Platform Exploited in Sophisticated Credential Harvesting Campaign
ID: a7fe5c2e-2925-51ca-84b4-4c51586472f8
STIX ID: report--a7fe5c2e-2925-51ca-84b4-4c51586472f8
Feed Name: KnowBe4 Blog
KnowBe4 Threat Lab investigated a focused phishing campaign that leveraged accounts on the legitimate EUSurvey platform to send emails containing unique (polymorphic) malicious links and hidden payloads that directed recipients to credential-harvesting pages. Attackers used an invoice-remittance lure, hidden white-text content, and an interactive verification step to bypass SPF/DKIM/DMARC, evade link scanners and SEGs; KnowBe4 Defend neutralized the emails and the credential-harvesting sites were blocked.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
