logo

Effective Phishing Campaign Targeting European Companies and Institutions

ID: 37ed6e92-a294-5120-a2f5-431990649678

STIX ID: report--37ed6e92-a294-5120-a2f5-431990649678

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2024-12-18

Date Updated: 2026-04-28

Author: Shachar Roitman, Ohad Benyamin Maimon and William Gamazo

...
...

Unit 42 investigated a large-scale phishing campaign (peaking June 2024 and active through September 2024) that used fake DocuSign lures and HubSpot Free Form URLs to harvest Microsoft credentials from ~20,000 European users across automotive, chemical, and industrial sectors; attackers used redirected .buzz domains, bulletproof hosting, VPN proxies and custom user-agents to perform Azure account takeovers, maintain persistence, and move laterally. The report includes detailed IoCs (URLs, IPs, PDF hashes), detection queries, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.