A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)
ID: 966c23b6-f9e0-5feb-b7c2-53e27fa870bd
STIX ID: report--966c23b6-f9e0-5feb-b7c2-53e27fa870bd
Feed Name: SANS ISC Diary
Threat Score
This report details a phishing campaign that used a Cloudflare Workers domain to host a React-based fake Dropbox Transfer page which collected credentials and geolocation data and exfiltrated them through the EmailJS API; observable IoCs include the workers.dev phishing domain and EmailJS service/template identifiers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
