Phishing Passwords With Maersk, Microsoft and Adobe
ID: a3f02bf3-a3ce-554b-8ad4-49f82e95ac31
STIX ID: report--a3f02bf3-a3ce-554b-8ad4-49f82e95ac31
Feed Name: WatchGuard Secplicity Blog
The report describes an ongoing phishing campaign targeting primarily Germany and Italy (with instances in APAC) that sends spoofed invoices from shipping companies and personalized links to credential-harvesting pages. Attackers deliver an HTML attachment disguised as a PDF which posts Adobe/Microsoft credentials to a third-party form host (jotformeu.com) or use hosted pages (drive.google.com, blob.core.windows.net, onedrive.live.com) and cloned Microsoft login pages to capture logins; defenders are advised to verify links and not submit credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
