Today > 8 Critical | 28 High | 31 Medium vulnerabilities   -   You can now download lists of IOCs here!

Inside the incident: Uncovering an advanced phishing attack

Dec. 11, 2024, 11:05 a.m.

Description

A sophisticated phishing campaign targeted a U.K.-based insurance company, using a compromised CEO's email account from a major shipping company. The attack involved a malicious PDF link hosted on AWS, leading to a fake Microsoft authentication page. The threat actor employed tactics like deletion rules, trusted sender addresses, and legitimate platforms to evade detection. The 'Russian nesting dolls' method was used, embedding multiple links to obscure the final phishing site. Swift action by the security team limited the attacker's success to creating a deletion rule. The incident was part of a broader campaign targeting multiple companies, highlighting the need for enhanced user awareness and technical measures to combat increasingly sophisticated phishing attempts.

Date

Published: Dec. 11, 2024, 2:51 a.m.

Created: Dec. 11, 2024, 2:51 a.m.

Modified: Dec. 11, 2024, 11:05 a.m.

Indicators

www.siffinance.com

ywnjb.siffinance.com

login.siffinance.com

siffinance.com