China-Sponsored Attackers Target 40K Corporate Users in 90 Days
ID: 2928b878-db08-5af5-9f66-c2b466615c46
STIX ID: report--2928b878-db08-5af5-9f66-c2b466615c46
Feed Name: Dark Reading
Date Published: 2024-06-27
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers identified three state-sponsored credential-phishing campaigns—LegalQloud, Eqooqp, and Boomer—that use highly evasive and adaptive techniques (AitM proxies, MFA bypass, dynamic phishing links, server-side generated pages, bot-detection evasion) to harvest Microsoft credentials from corporate users across multiple industries; the activity, linked to a group tracked as Storm-1101/DEV-1101, impacted tens of thousands of users and bypassed legacy URL filtering and other security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
