EclecticIQ analysts identified a phishing campaign in late October 2024 targeting the telecommunications and financial sectors. Attackers leveraged Google Docs to deliver phishing links, redirecting victims to fake login pages hosted on Weebly - a legitimate, user-friendly website builder service. By using Google’s trusted domain for initial delivery, attackers bypassed standard email filters and endpoint protections, leveraging reputable platforms to evade detection and increase user trust.
Financially Motivated Threat Actor Leveraged Google Docs and Weebly Services to Target Telecom and Financial Sectors
Submitted 4 weeks ago by Joker@sh.itjust.works to cybersecurity@infosec.pub