A phishing campaign used a fake .XPS file disguised as a PDF invoice to lure victims into visiting a credential harvesting page mimicking Adobe Reader. The attack bypassed anti-spam filters and used social engineering to steal email credentials. Defense recommendations include SPF record validation, user security training, DNS reputation filtering, and multi-factor authentication (MFA) for Office 365 and G Suite to limit damage even if credentials are compromised.

5m read timeFrom huntress.com
Post cover image
Table of contents
The BackstoryLayered Defense AdviceParting Thoughts
1 Impression