logo

Threat Actors Team Up for Post-Holiday Phishing Email Surge

ID: acbea160-1af5-5b08-8edd-538f2bd2b7dc

STIX ID: report--acbea160-1af5-5b08-8edd-538f2bd2b7dc

Feed Name: Dark Reading

Threat Score
55/100

Date Published: 2024-01-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Proofpoint observed a large post-holiday phishing campaign where TA866 leveraged TA571's traffic distribution system to send thousands of malicious emails to North American organizations; PDFs linked to OneDrive led to a downloader called WasabiSeed and a 'Screenshotter' payload. The campaign—blocked by Proofpoint—illustrates organized cybercrime actors outsourcing distribution via TDS networks and highlights seasonal activity pauses and returns among e-crime groups.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.