Cyble Research and Intelligence Labs uncovered a widespread credential harvesting campaign using HTML email attachments that bypass traditional security measures. Attackers impersonate trusted brands like Adobe, Microsoft, FedEx, and DHL through fake login pages embedded in HTML files. The malicious JavaScript captures
Table of contents
Technical findingsGeographic targetingConclusionOur Recommendations:MITRE ATT&CK® TechniquesIndicators of compromise (IoCs)Detection opportunitiesSort: