logo

International Threats – Infection URLs Used in Regional Phishing Campaigns

ID: f47f0b97-b944-5569-a6ba-261256380b42

STIX ID: report--f47f0b97-b944-5569-a6ba-261256380b42

Feed Name: Cofense Blog

Threat Score
70/100

Date Published: 2025-11-05

Date Updated: 2026-04-27

Author: Cofense

...
...

**Executive Summary:** This Cofense Intelligence report analyzes infection URLs used in high-volume non-English phishing campaigns (Spanish, Thai, Chinese, Portuguese, German) that bypassed secure email gateways to deliver malware, documenting that attackers commonly abuse legitimate cloud/file services (Google Drive/Docs, Dropbox, Amazon AWS, MediaFire, etc.) and compromised domains to host or redirect to payloads; it also outlines dominant malware families per language (for example Remcos, KrBanker, XWorm) and language-specific themes, underscoring the need for multilingual detection, user training, and improved email defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.