A phishing campaign used a fake .XPS file disguised as a PDF invoice to lure victims into visiting a credential harvesting page mimicking Adobe Reader. The attack bypassed anti-spam filters and used social engineering to steal email credentials. Defense recommendations include SPF record validation, user security training, DNS reputation filtering, and multi-factor authentication (MFA) for Office 365 and G Suite to limit damage even if credentials are compromised.
1 Impression