logo

Using Genuine Business Domains and Legitimate Services to Harvest Credentials

ID: d48a7186-9479-59bd-a4f2-ee4c0d7057f1

STIX ID: report--d48a7186-9479-59bd-a4f2-ee4c0d7057f1

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-01-28

Date Updated: 2026-04-28

Author: Martin Kraemer

...
...

The KnowBe4 Threat Lab analyzed a targeted phishing campaign active from October 2–3, 2024, which abused a compromised legitimate business domain and Mailgun email services to deliver Microsoft-branded credential-harvesting pages. Attackers created subdomains, leveraged an open redirect vulnerability, and used multiple delivery methods (malicious HTML attachments, QR-containing PDFs, hidden JavaScript, impersonated MS notifications) to bypass security controls and increase click rates; the campaign sent 170+ reported emails primarily to finance and healthcare organizations in the U.S. Recommendations include deploying EDR, monitoring DNS and outgoing email, and strengthening user phishing awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.