216.73.216.6

Pick your Poison - A Double-Edged Email Attack

· Published 28/04/2025 16:27 · Modified 28/04/2025 19:20

Export JSON

Essential information

Published
28/04/2025 16:27
Modified
28/04/2025 19:20
Tags
2025-04-08 2025-04-28 connectwise rat credential-theft file-sharing office365 phishing remote access social engineering
Related entities
5 techniques (mitre), 1 malware

Description

A sophisticated cyber-attack campaign has been identified, combining techniques targeting credentials with malware delivery. The attackers use a file deletion reminder as a pretext, exploiting a legitimate service to appear more credible. Upon opening a shared PDF file, users are presented with two hyperlinks: 'Preview' leads to a fake Microsoft login page for credential theft, while 'Download' initiates the installation of malware. The malware establishes persistence through system services and registry modifications. This dual-threat approach emphasizes the need for user vigilance and education in recognizing attempts and suspicious emails.

External references