logo

Major Phishing Campaign Exploiting Missing "X-Frame-Options" Headers Puts Global Companies at Risk

ID: 85d534a4-9734-51a3-b3f9-84544cbc1f4c

STIX ID: report--85d534a4-9734-51a3-b3f9-84544cbc1f4c

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2024-08-07

Date Updated: 2026-04-27

...
...

Threat actors are running a global phishing campaign that exploits missing X-Frame-Options headers to load victim domains in iframes and overlay fake login panels; harvested credentials are sent to a Telegram bot (hardcoded token/ChatID). The campaign has used VK Cloud and Firebase hosting, mass-mailing tools (SendGrid, PowerMTA, Gammadyne), targeted multiple corporate domains (1,262 victims identified), and has attribution signals pointing to a Telegram account tied to a Nigerian phone number.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.