Ask Huntress: Fake .XPS Invoice Leading to Credential Phishing
ID: 2ec1bba8-2810-5117-8461-d92c9b6cd55f
STIX ID: report--2ec1bba8-2810-5117-8461-d92c9b6cd55f
Feed Name: Huntress Blog
This report analyzes a phishing campaign that used a deceptive .XPS attachment named to resemble a PDF which, when opened, directed users to a credential-harvesting webpage (example URL: https://johic.usa.cc/VICTIMCOMPANY/Office/Share/share). The attacker spoofed company branding and solicited professional email credentials via a fake Adobe Reader pop-up; the site was later taken down. The report provides detection and mitigation recommendations including SPF checks, URL reputation filtering, user training, and multi-factor authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
