logo

Attackers Are Taking Over Real Email Threads to Deliver Phishing: New Enterprise Risk

ID: badb1411-faa7-5c2e-b940-c43282100306

STIX ID: report--badb1411-faa7-5c2e-b940-c43282100306

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-26

Author: ANY.RUN

...
...

ANY.RUN researchers detail an active "thread-hijack" phishing campaign in which attackers compromise a supplier mailbox, reply inside authentic C-suite email threads, and deliver multi-step redirected phishing links gated by Cloudflare Turnstile that culminate in an EvilProxy adversary-in-the-middle page to steal Microsoft credentials; the report highlights evasion techniques, provides detection guidance (behavioral detonation and TI feeds), and links the sample to a broader campaign with IOCs for hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.