logo

Pick your Poison - A Double-Edged Email Attack

ID: 8f5332d9-4dbc-5646-9454-ae5614d7849d

STIX ID: report--8f5332d9-4dbc-5646-9454-ae5614d7849d

Feed Name: Cofense Blog

Threat Score
70/100

Date Published: 2025-04-08

Date Updated: 2026-04-27

Author: Cofense

...
...

This Cofense Phishing Defense Center report details a dual-path phishing campaign that lures victims with a files.fm file-deletion reminder PDF which either directs victims to a fake Microsoft login to harvest Office365 credentials or downloads a disguised executable (SecuredOnedrive.ClientSetup.exe) that installs ConnectWise/ScreenConnect RAT. The report includes execution and persistence analysis (service and registry modifications), C2 endpoints, payload and infection URLs, IP addresses, and file hashes to support detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.