logo

New Phishing Attacks Stealing MFA Tokens Too

ID: ed3c8da9-7785-571a-b201-29aea5f9ef86

STIX ID: report--ed3c8da9-7785-571a-b201-29aea5f9ef86

Feed Name: WatchGuard Secplicity Blog

Threat Score
70/100

Date Published: 2019-06-06

Date Updated: 2026-05-01

Author: The Editor

...
...

A trending phishing campaign targeting primarily German users distributes a malicious PDF attached to emails purporting to be an invoice. The PDF prompts victims to open it in Acrobat Reader, uses embedded JavaScript to collect Amazon usernames, passwords and 2FA tokens, and sends them in clear text to an attacker-controlled domain that mimics Amazon via a deceptive subdomain; sandbox testing and packet captures confirm credential and 2FA exfiltration, allowing attackers to access victim accounts and likely siphon funds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.