Pick your Poison - A Double-Edged Email Attack
ID: 8f5332d9-4dbc-5646-9454-ae5614d7849d
STIX ID: report--8f5332d9-4dbc-5646-9454-ae5614d7849d
Feed Name: Cofense Blog
This Cofense Phishing Defense Center report details a dual-path phishing campaign that lures victims with a files.fm file-deletion reminder PDF which either directs victims to a fake Microsoft login to harvest Office365 credentials or downloads a disguised executable (SecuredOnedrive.ClientSetup.exe) that installs ConnectWise/ScreenConnect RAT. The report includes execution and persistence analysis (service and registry modifications), C2 endpoints, payload and infection URLs, IP addresses, and file hashes to support detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
