Multi Brand Themed Phishing Campaign Harvests Credentials
ID: 490ebe16-1bcf-532a-b50d-13f8e4a9948a
STIX ID: report--490ebe16-1bcf-532a-b50d-13f8e4a9948a
Feed Name: Cyble Blog
**Executive summary:** Cyble Research and Intelligence Labs identified a widespread credential-harvesting phishing campaign that sends RFC-compliant HTML attachments impersonating brands (Adobe, Microsoft, FedEx, WeTransfer, etc.) which run embedded JavaScript to capture user credentials and POST them to attacker-controlled Telegram bots; samples show AES obfuscation, anti-analysis controls (blocking devtools and keyboard shortcuts), and use of multiple bot tokens and chat IDs, primarily targeting organizations in Central and Eastern Europe across many sectors. The report provides sample details, IoCs (attachment name patterns, Telegram API usage, bot tokens), a YARA detection rule, and practical recommendations including blocking/sandboxing HTML attachments and monitoring/inspecting Telegram API traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
