Using StackBlitz to Launch Phishing Campaigns
ID: 35d6e2f8-55b7-5ae4-9d8a-e44ad46adf1f
STIX ID: report--35d6e2f8-55b7-5ae4-9d8a-e44ad46adf1f
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz observed multiple active phishing campaigns that host credential-harvesting pages on StackBlitz by abusing its preboot/CachedFetch functionality to deliver server-side pages as JSON and redirect victims to fake login portals (Outlook, OneDrive/Office365, Gmail, Yahoo, etc.). The report documents two spam delivery methods (OneDrive-themed lures), shows traffic and source code analysis, and lists many StackBlitz subdomains and additional malicious domains as IOCs to aid detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
