logo

New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs

ID: 6508b667-6434-5570-8e72-a8e5cfdf5222

STIX ID: report--6508b667-6434-5570-8e72-a8e5cfdf5222

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

...
...

Abnormal researchers uncovered a credential‑harvesting campaign (Nov 2025–Mar 2026) targeting C‑suite and senior executives using a closed‑access phishing‑as‑a‑service named Venom. The platform delivered SharePoint‑themed QR‑code lures and used extensive personalization, randomized HTML, fabricated email threads, and human‑verification checks to evade detection; it then bypassed or neutralized MFA via adversary‑in‑the‑middle and device‑code flows to obtain persistent access, and its licensing/management features indicate potential for wider proliferation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.