The SharePoint Lure That Never Touched Microsoft
ID: 7885bbac-1cb1-5cc8-b5a2-09a9491d1d44
STIX ID: report--7885bbac-1cb1-5cc8-b5a2-09a9491d1d44
Feed Name: IRONSCALES
Threat Score
A hijacked nonprofit mailbox was used to send an image-only SharePoint-styled phishing lure that linked to a public Freelo shared page hosting an unrelated fax-style second-stage; rasterizing the entire call-to-action evaded text-based filters and URL scanners, while the recipient's gateway altered authentication results making the message appear spoofed. Adaptive AI flagged it as credential theft (89%); IOCs include the Freelo shared URL and the genuine nonprofit sender address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
