"EvilProxy Exploits Open Redirect on indeed.com for Microsoft 365 Phishing"

1 min read
Source: BleepingComputer
"EvilProxy Exploits Open Redirect on indeed.com for Microsoft 365 Phishing"
Photo: BleepingComputer
TL;DR Summary

A phishing campaign targeting Microsoft 365 accounts of key executives in U.S.-based organizations has been discovered, utilizing open redirects from the Indeed employment website. The campaign leverages the EvilProxy phishing service to collect session cookies, bypassing multi-factor authentication. Executives from various industries are being targeted, and the phishing emails contain a legitimate-looking indeed.com link that redirects to a phishing site mimicking Microsoft's login page. The use of reverse proxy kits for phishing, combined with open redirects, is increasing the success of such campaigns.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

80%

40583 words

Want the full story? Read the original article

Read on BleepingComputer