logo

Phishers Get Creative: The NoteGPT Twist You Didn’t See Coming

ID: e6dcde68-a78a-56b6-8928-9b590de1edbf

STIX ID: report--e6dcde68-a78a-56b6-8928-9b590de1edbf

Feed Name: Cofense Blog

Threat Score
60/100

Date Published: 2025-12-09

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense Phishing Defense Center reports a phishing campaign that leverages NoteGPT to host malicious “documents” which impersonate Microsoft OneDrive notifications; when users click “View Document” they are redirected to a NoteGPT page and then to a Microsoft-looking credential phishing site (malicious example URL: arc.stylized.it.com). The campaign exploits user trust in legitimate services and branding to harvest credentials, and Cofense recommends verifying senders and links and employing phishing detection and response to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.