Operation DoppelBrand Weaponizes Trusted Brands For Credential Theft
ID: 0d014183-1714-54e3-8b42-1fba1b9609a9
STIX ID: report--0d014183-1714-54e3-8b42-1fba1b9609a9
Feed Name: Infosecurity Magazine (News)
SOCRadar uncovered "Operation DoppelBrand," a financially motivated phishing campaign attributed to GS7 that targeted major US financial institutions, insurers and technology firms from December 2025 to January 2026. The actor used over 150 lookalike domains, automated registrars and short-lived SSL certificates to host cloned login portals and fake OneDrive flows that harvest credentials and device telemetry forwarded to Telegram bots; attackers then often deploy legitimate remote access software (e.g., LogMeIn Resolve) via MSI installers and VBS loaders to gain persistent access and sell or transfer access to affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
