logo

Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft

ID: 0d014183-1714-54e3-8b42-1fba1b9609a9

STIX ID: report--0d014183-1714-54e3-8b42-1fba1b9609a9

Feed Name: Infosecurity Magazine (News)

Threat Score
72/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

...
...

SOCRadar uncovered "Operation DoppelBrand," a financially motivated phishing campaign attributed to GS7 that targeted major US financial institutions, insurers and technology firms from December 2025 to January 2026. The actor used over 150 lookalike domains, automated registrars and short-lived SSL certificates to host cloned login portals and fake OneDrive flows that harvest credentials and device telemetry forwarded to Telegram bots; attackers then often deploy legitimate remote access software (e.g., LogMeIn Resolve) via MSI installers and VBS loaders to gain persistent access and sell or transfer access to affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.