Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
- Unit 42 says phishing campaign targeted automotive, chemical, and industrial compound manufacturing industries
- More than 20,000 victims were successfully targeted
- The campaign has been disrupted, but users should still be on their guard
Hackers of potentially Russian or Ukrainian origin have been targeting UK and EU organizations in the automotive, chemical, and industrial compound manufacturing industries with advanced phishing threats, experts have warned.
A report from Unit 42, Palo Alto Networks’ cybersecurity arm, claims to have observed a campaign that started in June 2024, and was still active as of September. The goal of the campaign was to grab people’s Microsoft Azure cloud accounts, and steal any sensitive information found there.
The crooks would either send a Docusign-enabled PDF file, or an embedded HTML link, which would redirect the victims to a HubSpot Free Form Builder link. That link would usually invite the reader to “View Document on Microsoft Secured Cloud,” where the victims would be asked to provide their Microsoft Azure login credentials.
Bulletproof hosting
The majority of the victims are located in Europe (mostly Germany), and the UK. Roughly 20,000 users were “successfully targeted”, the researchers said, adding that at least in a few cases, the victims provided the attackers with login credentials: “We verified that the phishing campaign did make several attempts to connect to the victims’ Microsoft Azure cloud infrastructure,” the researchers said in their writeup.
Besides using custom phishing lures, with organization-specific branding and email formats, the crooks also went for targeted redirections using URLs designed to look like the victim organization’s domain. Furthermore, the miscreants used bulletproof VPS hosts, and reused their phishing infrastructure for multiple operations. Most of the phishing pages were hosted on .buzz domains.
At press time, most of the attack infrastructure was pulled offline – Unit 42 said it worked together with HubSpot to address the abuse of the platform, and engaged with compromised organizations to provide recovery resources. Since most phishing servers are now offline, the researchers said the disruption efforts were effective.
Via The Register
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
Unit 42 says phishing campaign targeted automotive, chemical, and industrial compound manufacturing industries More than 20,000 victims were successfully targeted The campaign has been disrupted, but users should still be on their guard Hackers of potentially Russian or Ukrainian origin have been targeting UK and EU organizations in the automotive,…
Recent Posts
- Summer Game Fest Live 2026: The biggest news, trailers, and announcements
- OpenAI rolls out a Lockdown Mode for extra protection against prompt injection attacks
- The Dyson HushJet Mini Cool is the powerful personal fan you won’t want to live without this summer — and it’s surprisingly reasonably priced, too
- Gone in 60 minutes
- GroWell Cap Review: I Have Hair for the First Time in 15 Years
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023