Operation DoppelBrand: Weaponizing Fortune 500 Brands
ID: 8f3f291c-1e6c-5207-8509-e2ab71eeb14b
STIX ID: report--8f3f291c-1e6c-5207-8509-e2ab71eeb14b
Feed Name: Dark Reading
Operation DoppelBrand is an ongoing, sophisticated phishing campaign run by a group called GS7 that targets Fortune 500 and other high-value organizations—primarily in English-speaking markets—by creating highly convincing, brand-impersonating login portals. The actors register large numbers of malicious domains, route traffic through Cloudflare to mask infrastructure, exfiltrate harvested credentials and telemetry to Telegram bots, and deploy RMM tools to enable remote access or resale of access to affiliates, indicating a high-risk, financially motivated criminal operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
