216.73.216.6

Threat Actors Exploit Government Website Vulnerabilities for Phishing Campaigns

· Published 29/01/2025 17:31 · Modified 29/01/2025 19:32

Export JSON

Essential information

Published
29/01/2025 17:31
Modified
29/01/2025 19:32
Tags
.gov domains 2025-01-29 CVE-2024-25608 agent tesla keylogger credential-theft email security government websites liferay open redirects phishing stormkitty
Related entities
1 vulnerabilities (cve), 4 observables, 6 techniques (mitre), 2 malware, 4 others

Description

Threat actors are exploiting vulnerabilities in , particularly .gov domains, to conduct campaigns. The abuse primarily involves using to bypass secure email gateways and lead victims to credential pages. A significant portion of these exploits may be related to , affecting the digital platform. US government domains, while less frequently abused, are primarily used for in Microsoft-themed attempts. Brazilian government domains are the most frequently abused, followed by other countries. Some compromised government email addresses have also been used as command and control servers for malware like and .

External references