Is That Really ProtonMail? New Credential Harvesting Threats Targeting Cloud Apps
ID: 44c70c54-0bd0-5283-9ade-dcd981a47a19
STIX ID: report--44c70c54-0bd0-5283-9ade-dcd981a47a19
Feed Name: Security Boulevard
Threat Score
This SlashNext blog post details active credential-harvesting campaigns where attackers abuse cloud services—especially Gravatar—to host convincing impersonations of ProtonMail, telecom providers (AT&T, Comcast Xfinity) and regional ISPs, outlines the phishing mechanics and customized impersonation techniques used to evade detection, and recommends user and enterprise mitigations (URL checks, cautious email handling, strong unique passwords, and 2FA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
