logo

Malvertising Campaign Builds a Phish for Lowe's Employees

ID: 99b622c6-c96a-56e6-aa76-9b129f302918

STIX ID: report--99b622c6-c96a-56e6-aa76-9b129f302918

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-09-05

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Malwarebytes researchers observed a phishing campaign that leveraged sponsored Google search ads to surface typosquatting sites mimicking Lowe's MyLowesLife employee portal. Victims who clicked the ads were presented with realistic login pages requesting account numbers, passwords, and answers to security questions; submitted data was forwarded to an attacker-controlled phishing kit. The report lists the malicious domains (myloveslife.net, mylifelowes.org, mylifelowes.net, myliveloves.net) and notes attackers used generic AI-generated homepages to hinder detection and takedown efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.