Catching a phish with many faces
ID: 4604e3bb-cd4e-5323-b794-c2bcba0350ab
STIX ID: report--4604e3bb-cd4e-5323-b794-c2bcba0350ab
Feed Name: WeLiveSecurity (ESET Research)
This article describes how attackers use dynamic phishing kits and phishing-as-a-service platforms (e.g., LogoKit) to generate on-the-fly, customized fake login pages that pull company logos via public APIs, pre-fill victim details, exfiltrate credentials by AJAX POST, and then redirect victims to legitimate sites; it highlights the technique's scalability and evasion advantages and recommends defensive measures such as independent link verification, unique passwords, and app- or hardware-based 2FA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
