logo

GreenSpot APT Targets NetEase 163.com Users with Fake Download Pages & Spoofed Domains

ID: b086164c-16a0-51d2-ae13-7dd2a4d6bb05

STIX ID: report--b086164c-16a0-51d2-ae13-7dd2a4d6bb05

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

Hunt.io research attributes a credential-harvesting phishing campaign to the GreenSpot APT, which impersonates NetEase (163.com) services via rapidly-registered domains and spoofed login/download pages; the report documents attacker infrastructure (domains, IPs, TLS certificate behaviors), malicious JavaScript/PHP that captures credentials, example decoy files, and a table of IOCs, and recommends enabling MFA and enhanced monitoring to mitigate this targeted campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.