logo

Inside the incident: Uncovering an advanced phishing attack

ID: cedb2976-1011-5ae5-af66-17f95ab138ce

STIX ID: report--cedb2976-1011-5ae5-af66-17f95ab138ce

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-12-10

Date Updated: 2026-03-27

Author: Sponsored by Varonis

...
...

This Varonis incident report describes a sophisticated phishing campaign that targeted multiple organizations by sending a high-quality email with a link to a malicious PDF hosted on AWS; the PDF redirected victims to a realistic fake Microsoft authentication page hosted via Render, resulting in credential theft and at least one account takeover. The attacker used the compromised account to create a mailbox deletion rule (to erase traces), leveraged legitimate cloud platforms to evade detection, and attempted lateral impact; Varonis identified IoCs (IP 138.199.52.3 and several siffinance-related domains), contained the intrusion within ~30 minutes, and recommended user awareness, MFA, robust email security, and other technical mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.