logo

Phishing – Ask and ye shall receive

ID: 89e86549-a2eb-52f8-9b5c-3e6b07feea89

STIX ID: report--89e86549-a2eb-52f8-9b5c-3e6b07feea89

Feed Name: Fox-IT blog

Threat Score
50/100

Date Published: 2018-08-14

Date Updated: 2026-04-27

...
...

This report describes Fox-IT's Invoke-CredentialPhisher, a PowerShell-based post-exploitation tool and Cobalt Strike module that leverages authentic-looking Windows toast notifications and real credential prompt dialogs to trick users into submitting credentials. The write-up details technical implementation (base64 in-memory loading of a PoshWinRT wrapper, AppID and icon spoofing, hide/show process techniques), sample phishing scenarios (Outlook reconnect, updates, password expiry), command-line examples, and recommends enabling PowerShell logging and increasing user awareness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.