logo

More Than Music: The Unseen Cybersecurity Threats of Streaming Services

ID: df7c7494-f923-557b-bcab-4313ef6d86cb

STIX ID: report--df7c7494-f923-557b-bcab-4313ef6d86cb

Feed Name: Cofense Blog

Threat Score
55/100

Date Published: 2025-04-02

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense PDC observed a phishing campaign impersonating Spotify that used spoofed email headers and legitimate-looking content to trick recipients into clicking a malicious link (initially hosted at 40.82.178.115 and routed via a Linktree URL) which redirected to Azure App Service pages cloned to resemble Spotify. The landing pages harvested credentials, credit card details, and bank-issued transaction passwords, sending the data to a PHP-based C2; the report includes multiple IOCs (URLs, IPs, and Azure hostnames) and highlights the tactics used to obfuscate malicious links and capture financial information.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.