logo

Phishing Deep Dive: EU-Affiliated Survey Platform Exploited in Sophisticated Credential Harvesting Campaign

ID: a7fe5c2e-2925-51ca-84b4-4c51586472f8

STIX ID: report--a7fe5c2e-2925-51ca-84b4-4c51586472f8

Feed Name: KnowBe4 Blog

Threat Score
55/100

Date Published: 2025-06-18

Date Updated: 2026-04-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Lab investigated a focused phishing campaign that leveraged accounts on the legitimate EUSurvey platform to send emails containing unique (polymorphic) malicious links and hidden payloads that directed recipients to credential-harvesting pages. Attackers used an invoice-remittance lure, hidden white-text content, and an interactive verification step to bypass SPF/DKIM/DMARC, evade link scanners and SEGs; KnowBe4 Defend neutralized the emails and the credential-harvesting sites were blocked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.