Self-contained HTML phishing attachment using Telegram to exfiltrate stolen credentials, (Mon, Oct 28th)

SANS Internet Storm Center, InfoCON: green 2024-10-28

Summary:

Phishing authors have long ago discovered that adding HTML attachments to the messages they send out can have significant benefits for them – especially since an HTML file can contain an entire credential-stealing web page and does not need to reach out to the internet for any other reason than to send the credentials a victim puts in a login form to an attacker-controlled server[1]. Since this approach can be significantly more effective than just pointing recipients to a URL somewhere on the internet, the technique of sending out entire credential-stealing pages as attachments has become quite commonplace.

Link:

https://isc.sans.edu/diary/rss/31388

From feeds:

Intel Hub » T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

10/28/2024, 05:46

Date published:

10/28/2024, 03:13