Phishing Page Changes as per User's Email Address

09 February 2023
ASEC stumbled across phishing emails warning users that their accounts would be shut down unless they perform a particular action. Hackers used Google's favicon feature to trick users into revealing their credentials. The account credentials entered on the phishing page were sent to a C2 whose address was the same domain as a previous campaign observed by the researchers.