Custom-Crafted, Qantas-Spoofing Emails Target Australian Victims
ID: 1150f08e-8b96-5a8f-a908-b1ef07ae5f7e
STIX ID: report--1150f08e-8b96-5a8f-a908-b1ef07ae5f7e
Feed Name: Cofense Blog
A credential-phishing campaign spoofing Qantas marketing emails targeted primarily Australian employees, bypassing multiple SEGs (Microsoft ATP, Proofpoint, Mimecast) to drive victims to short-lived phishing sites sharing an “auth/auhs1” path. The emails closely mimicked Qantas branding and included unsubscribe headers (subscriptions.pstmrk.it) to boost legitimacy. The phishing flow collected contact details and DOB before soliciting credit card data and simulating MFA, indicating a financially motivated operation with potential for follow-on attacks using harvested PII.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
