logo

Phishing Passwords With Maersk, Microsoft and Adobe

ID: a3f02bf3-a3ce-554b-8ad4-49f82e95ac31

STIX ID: report--a3f02bf3-a3ce-554b-8ad4-49f82e95ac31

Feed Name: WatchGuard Secplicity Blog

Threat Score
50/100

Date Published: 2019-03-14

Date Updated: 2026-05-01

Author: The Editor

...
...

The report describes an ongoing phishing campaign targeting primarily Germany and Italy (with instances in APAC) that sends spoofed invoices from shipping companies and personalized links to credential-harvesting pages. Attackers deliver an HTML attachment disguised as a PDF which posts Adobe/Microsoft credentials to a third-party form host (jotformeu.com) or use hosted pages (drive.google.com, blob.core.windows.net, onedrive.live.com) and cloned Microsoft login pages to capture logins; defenders are advised to verify links and not submit credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.