Security News > 2023 > October > EvilProxy uses indeed.com open redirect for Microsoft 365 phishing

EvilProxy uses indeed.com open redirect for Microsoft 365 phishing
2023-10-03 13:00

A recently uncovered phishing campaign is targeting Microsoft 365 accounts of key executives in U.S.-based organizations by abusing open redirects from the Indeed employment website for job listings.

In August 2023, Proofpoint warned of another EvilProxy campaign, which distributed approximately 120,000 phishing emails to hundreds of organizations, targeting their employees' Microsoft 365 accounts.

The use of reverse proxy kits for phishing is growing and combining them with open redirects increases the success of a campaign.

EvilProxy phishing campaign targets 120,000 Microsoft 365 users.

Microsoft Teams phishing attack pushes DarkGate malware.

W3LL phishing kit hijacks thousands of Microsoft 365 accounts, bypasses MFA. Classiscam fraud-as-a-service expands, now targets banks and 251 brands.


News URL

https://www.bleepingcomputer.com/news/security/evilproxy-uses-indeedcom-open-redirect-for-microsoft-365-phishing/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 473 68 2214 4928 253 7463