logo

Is That Really ProtonMail? New Credential Harvesting Threats Targeting Cloud Apps

ID: 44c70c54-0bd0-5283-9ade-dcd981a47a19

STIX ID: report--44c70c54-0bd0-5283-9ade-dcd981a47a19

Feed Name: Security Boulevard

Threat Score
55/100

Date Published: 2025-01-22

Date Updated: 2026-04-22

Author: Stephen Kowski

...
...

This SlashNext blog post details active credential-harvesting campaigns where attackers abuse cloud services—especially Gravatar—to host convincing impersonations of ProtonMail, telecom providers (AT&T, Comcast Xfinity) and regional ISPs, outlines the phishing mechanics and customized impersonation techniques used to evade detection, and recommends user and enterprise mitigations (URL checks, cautious email handling, strong unique passwords, and 2FA).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.