Purchase order attachment isn’t a PDF. It’s phishing for your password
ID: c3fb2f5e-2a7a-5621-98f3-8e8c00222965
STIX ID: report--c3fb2f5e-2a7a-5621-98f3-8e8c00222965
Feed Name: Security Boulevard
This Malwarebytes blog post details a phishing campaign in which a malicious attachment named like “New PO 500PCS.pdf.hTM” opens an HTML page that prompts for credentials, harvests email/password combos plus IP/geolocation and browser details, and exfiltrates them to an attacker-controlled Telegram bot; victims are then shown a bogus invoice image to delay detection. The report highlights indicators (double file extension, browser-based login prompt, Telegram C2), explains attacker behavior, and offers practical mitigations such as checking file extensions, using MFA, and employing updated web-protection/anti-malware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
