HomeSecurityNew phishing campaign "HubPhish" targets European companies

New phishing campaign “HubPhish” targets European companies

Palo Alto Networks researchers have uncovered a new phishing campaign dubbed “HubPhish,” which targets European companies with the aim of stealing credentials and gaining access to victims’ Microsoft Azure infrastructure

HubPhish

The “HubPhish” campaign leverages tools from the HubSpot, seeking to influence at least 20,000 users from industries such as the automotive, chemical, and industrial compound manufacturing industries.

See more: Phishing attack targets Youtube creators

The peak of attacks was observed in June 2024, using fake forms created through HubSpot Free Form Builder.

The attacks include deceptive Docusign-themed emails that redirect users to fake Office 365 login pages to collect their credentials. Although HubSpot tools were used, it is clarified that neither the HubSpot platform nor the Free Form Builder links have been compromised.

Read more: Securonix discovered a new phishing campaign, known as “FLUX#CONSOLE”

The perpetrators used 17 active forms to redirect victims to malicious websites, many of which were hosted on “.buzz” domains.

After gaining access to user accounts, attackers install new devices on the accounts to ensure persistence and perform lateral movement within the cloud infrastructure. Additionally, they use Bulletproof VPS host infrastructure to gain access to compromised Azure tenants.

Phishing techniques are constantly evolving, with perpetrators exploiting services like Google Calendar and Google Drawings.

See related: Hackers exploit Google Calendar for phishing attacks

Users are receiving meeting invitations that include malicious links. These links bypass email security systems and lead to fake pages designed for financial fraud.

HubPhish

To protect themselves from these types of attacks, users are advised to enable the “known senders” setting in Google Calendar, thus reducing the risk of becoming victims of these sophisticated phishing attacks.

Read also: Europe: Authorities arrest members of “phishing gang”

Source: thehackernews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS