HubSpot phishing targets 20,000 Microsoft Azure accounts
ID: 30468ecc-b078-5fc0-9bdc-90f3a3cc1285
STIX ID: report--30468ecc-b078-5fc0-9bdc-90f3a3cc1285
Feed Name: Bleeping Computer
A widespread phishing campaign (June–Sept 2024) leveraged HubSpot Form Builder links and DocuSign-mimicking PDFs to redirect victims to credential-harvesting pages impersonating Microsoft Outlook/Azure; Unit 42 attributes about 20,000 compromised accounts across automotive, chemical, and industrial manufacturing firms in Europe, notes use of VPNs and password-reset attempts during takeovers, and identifies infrastructure artifacts ('.buzz' domains, a novel ASN, and unusual user-agent strings) useful for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
