Between June 18, 2026 and July 01, 2026, our team analyzed eleven distinct phishing campaigns targeting organizations across Nevada, Illinois, Minnesota, Texas, Kentucky, and Florida, with the majority of activity clustering in the final days of the window. The dominant capture mechanism across campaigns was a sequential multi-stage form-POST flow: attacker-controlled endpoints, typically processmail[.]php and process[.]php, received cleartext credential submissions in order — password first, OTP or MFA token second — with several kits deliberately returning a false "Incorrect Password" error on the first submission to coerce a second entry and double the credential yield before advancing the victim to the authentication-bypass stage. Impersonated brands and services drawn directly from on-page evidence include Microsoft 365, Netflix, Apple security products, Adobe, Greenvelope, Punchbowl, Texthelp-family applications including ReadWrite, EquatIO, BrowseAloud, and ReachDeck, and a range of email providers spanning Outlook, Office 365, Google, Yahoo Mail, and AOL.
A credential-harvesting page impersonating Microsoft 365 targeted a Nevada organization, walking victims through a multi-stage flow that collected a password, an OTP code, and a Microsoft Authenticator push-approval in sequence. Activity was confined to July 01, 2026. The victim's pre-filled email address appeared on every screen from the first load, meaning the kit had already associated the URL token in performancegolfzone[.]it.com/0F6nWQNJMR377XFVtHGiJDJw9c8MNU0-bl3q5vZQ2zF2YuA_XVfJD9geffr62QZ1bKN4bx0Y45G5F756LX0GANLzSR5pPc_iyxvo784u10mz1jLad621O2NqQw0n0rlBZv91jXE9cF7rHPnNnxH51XK9x39gct1nNgHt1aAU0dLwr3Il2kgSsZq0lhPDQtXUY849h01E5h0T441Qj3ukLjrE3uKKyayNYsYc/access with a specific target before delivery.
A credential-harvesting page impersonating a Texthelp-family web application — identifiable by the extensive suite of product-specific CSS theme variables for ReadWrite, EquatIO, Browseалoud, ReachDeck, and related tools present in the page source — targeted an Illinois organization via the domain proctectedlinkviews[.]de. Activity was confined to July 01, 2026, with a single observed event suggesting a targeted delivery rather than a broad spray campaign. The page loads a blurred full-screen background image sourced from a local relative path ("Image/imageedit_3_2453183620.jpg") and centers a semi-transparent overlay panel, a layout consistent with a login-prompt lure designed to present a convincing portal facade. The HTML retrieved does not surface a visible form POST target or JavaScript exfiltration call in the captured markup, which is consistent with a multi-stage page where credential collection logic loads dynamically after initial victim interaction or is housed in a secondary resource not present in this snapshot.
A tech-support scareware page impersonating Apple security products targeted a Minnesota organization, presenting a fabricated antivirus interface branded "Apple_security" and "MacOS_Spyware" alongside a prominently displayed toll-free number to drive victims toward a vishing call rather than automated credential capture. Activity was confined to June 29, 2026. The page is delivered through Azure Front Door infrastructure under azurefd[.]net, carries a noindex/nofollow robots meta tag to suppress search-engine indexing, and references a Plausible Analytics custom domain at invoice-display-1[.]com as well as an active Tawk.to live-chat widget keyed to workspace ID 69b16b749b4bdc1c397b4b1b, which gives the operator a real-time chat channel to any victim who remains on the page — meaning the human on the other end of that chat or phone number is where credential and payment collection actually occurs, and the browser-lock behavior exists solely to keep the victim present long enough to make that contact.
A credential-harvesting page impersonating a shared-invitation portal targeted an Illinois organization, presenting a blurred background image with a centered overlay card and a set of branded sign-in buttons drawn from multiple identity providers including Microsoft, Google, and several education-sector platforms including Read&Write, Equatio, and Browsealoud. Activity was confined to June 29, 2026, with a single detection observed. The page renders multiple OAuth-branded buttons styled to match legitimate single-sign-on workflows, each visually differentiated by color and provider icon, with the apparent intent of capturing credentials regardless of which identity provider the victim selects. The Cloudflare Turnstile challenge token embedded in the URL (`__cf_chl_f_tk`) functions as an evasion layer, ensuring the page resolves only for visitors who arrive through the gated link and blocking automated scanners that lack a valid token.
A credential-harvesting page impersonating both Adobe and Greenvelope, the online invitation platform, targeted a Texas organization through a fake e-invitation lure designed to prompt email login across multiple providers including Outlook, Office 365, Yahoo, AOL, and generic mail. Activity was confined to June 27, 2026. The primary capture mechanism is a form POST to processmail.php on the attacker-controlled domain celeebrationpartyy[.]one, with credentials submitted in cleartext over that same infrastructure; a second POST endpoint, process.php, collects OTP codes, meaning the kit is built to harvest both the primary password and any SMS-based second factor in sequence. The kit engineers two credential submissions by design: the first submission always returns an "Incorrect Password" message client-side regardless of what the user enters, which coerces a second attempt and doubles the likelihood of capturing a valid password before advancing the victim to the OTP stage.
A credential-harvesting page impersonating a Windows helpdesk support portal targeted an Illinois and Kentucky organization, delivered via paid Facebook advertising traffic as indicated by the fbclid and utm_source=fb parameters embedded in the landing URL. Detections occurred on June 18, 2026, June 25, 2026, and June 26, 2026, totaling 4 observed events across that window. The page is built on a compiled Vite/React bundle, with all credential-capture logic deferred to the minified JavaScript module index-DvsLmbh3.js, which prevents static analysis of the form POST target or exfiltration endpoint from the HTML alone. The attacker hosted the kit on Azure Static Web Apps under the z13.web.core.windows.net subdomain, a Microsoft-owned domain that carries implicit trust with many email security gateways and browser-based safe-browsing filters.
Related subdomain variants:
A credential-harvesting page impersonating Netflix targeted a Kentucky organization, presenting a full Netflix login form complete with the Netflix Sans typeface loaded from attacker-controlled relative paths and a background image drawn from the same local asset directory. Activity was confined to June 26, 2026. The actual page content is stored base64-encoded inside a data-html-b64 attribute on a script tag in the outer shell document, a delivery pattern that lets the browser decode and render the Netflix clone on the client side while keeping the phishing markup out of the raw HTTP response body and away from scanners that inspect response content directly. The hosting infrastructure sits on a cPanel shared-hosting node at 40-81-246-96.cpanel[.]site under the subdomain strmnflxsd.chf, with the session scoped to a UUID-style path segment that functions as a per-target token, allowing the operator to invalidate or swap the lure without changing the domain.
A credential-harvesting page impersonating Greenvelope, a legitimate online invitation and greeting card service, targeted a Minnesota organization by presenting a multi-provider email login lure backed by a PHP relay kit. Activity was confined to June 25, 2026. The primary capture mechanism is a modal form that POSTs email address and password fields to processmail[.]php on the attacker-controlled host metrxevent51[.]top, with a deliberate double-submission flow: the first submission always returns an "Incorrect Password" error to prompt the victim to re-enter credentials, ensuring the attacker collects both the initial entry and a confirmation attempt before the form advances.
A credential-harvesting page impersonating multiple email providers — Outlook, Office 365, Yahoo Mail, AOL, and a generic mail option — used a Punchbowl invitation lure to target a Texas organization, with an Adobe logo embedded in the page header creating an additional layer of brand confusion. Activity was confined to June 24, 2026. The primary capture mechanism is a form POST to processmail.php on the attacker-controlled domain hovex[.]sbs, with credentials serialized via jQuery's form.serialize() and transmitted over AJAX; a second POST to process.php then collects the OTP the victim enters after being told to expect a one-time code on their phone. The kit implements a deliberate double-submit pattern: the first credential submission always returns an "Incorrect Password" message, prompting the victim to re-enter credentials before the form advances to the MFA stage — a technique that increases the probability of capturing a valid, carefully re-typed password alongside a live OTP.
A credential-harvesting page impersonating Greenvelope, a legitimate online invitation service, targeted a Minnesota organization by presenting a multi-provider email login portal that also carried vestigial Adobe branding in its logo alt text, suggesting the lure may have been adapted from an earlier Adobe-themed kit. Activity was confined to June 22, 2026. The primary capture mechanism is a jQuery AJAX POST to processmail.php on attacker-controlled infrastructure, and the kit is deliberately built to run the victim through two credential submissions before proceeding: on the first submit the page always returns an "Incorrect Password" error regardless of what was entered, forcing a second submission and thereby harvesting whatever the user types in each attempt as a separate record.
A credential-harvesting page impersonating Microsoft 365 targeted a Florida organization, walking victims through a fully scripted multi-stage flow that collected username, password, and MFA tokens in sequence. Activity was confined to June 22, 2026. The kit — hosted on secondsightsystilqemsllc[.]vu, a .vu ccTLD domain constructed to resemble a legitimate business name — submits each stage's input through obfuscated JavaScript handlers whose function names are randomized per build, with exfiltration endpoints encoded in base64 strings embedded in the page config (prop_status_715 decodes to the redirect target, prop_count_778 carries what appears to be a session token, and the external JS files 5jtdPHBjaaUKRlf.js and m3EVNjfjC7jTgvaK.js carry the actual POST logic, obscured behind randomized variable and function name maps).
Learn how PhishID can help protect your district from cutting-edge threats like these! Schedule a Demo