logo

Punchbowl Phishing Attack Explained: How Digital Invites Are Used to Steal Credentials

ID: 014aee67-1dce-5d5f-ae3b-f7114c567f45

STIX ID: report--014aee67-1dce-5d5f-ae3b-f7114c567f45

Feed Name: Cofense Blog

Threat Score
55/100

Date Published: 2026-02-24

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense Phishing Defense Center analyzed a phishing campaign that leverages digital invitation platforms to trick recipients into clicking RSVP links which redirect to credential-harvesting pages impersonating popular providers (Microsoft, Google, Yahoo, AOL, Dropbox). The report includes screenshots of the phishing pages, whois information for malicious domains, observed infection and payload URLs (hXXp://t.ly/KwKzQ and hXXps://dry.za.com/if1/) with associated IPs, explains likely attacker motives (credential theft, resale, BEC), and provides user-focused mitigations such as verification of invites, careful inspection of login redirects, password resets, and enabling MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.