Phishers Wreak 'Havoc,' Disguising Attack Inside SharePoint
ID: 49f7f7d7-8284-5f2a-86d4-4fd29326eabf
STIX ID: report--49f7f7d7-8284-5f2a-86d4-4fd29326eabf
Feed Name: Dark Reading
Threat Score
Date Published: 2025-03-03
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
...
...
**Executive Summary:** A sophisticated phishing campaign delivers a ClickFix-style lure via SharePoint-hosted HTML documents that instruct victims to paste a PowerShell command, which then fetches and executes a modified Havoc command-and-control framework; the operator further hides C2 traffic by abusing the Microsoft Graph API and legitimate SharePoint hosting to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
