logo

Operation DoppelBrand: Weaponizing Fortune 500 Brands

ID: 8f3f291c-1e6c-5207-8509-e2ab71eeb14b

STIX ID: report--8f3f291c-1e6c-5207-8509-e2ab71eeb14b

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-02-16

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Operation DoppelBrand is an ongoing, sophisticated phishing campaign run by a group called GS7 that targets Fortune 500 and other high-value organizations—primarily in English-speaking markets—by creating highly convincing, brand-impersonating login portals. The actors register large numbers of malicious domains, route traffic through Cloudflare to mask infrastructure, exfiltrate harvested credentials and telemetry to Telegram bots, and deploy RMM tools to enable remote access or resale of access to affiliates, indicating a high-risk, financially motivated criminal operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.