PULSE NAME
Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond
WHITE Scattered Spider AlienVault 2024-11-07 Modified: 2024-12-07
223
IOCs
HIGH VOLUME
This analysis examines phishing tactics used by threat actors, particularly focusing on the 0ktapus group. It outlines techniques for investigating phishing campaigns by pivoting between landing pages, using 0ktapus as a case study. The methods discussed include application fingerprinting, network profiling, and domain registration analysis. The research reveals various DOM templates used by 0ktapus over time and provides insights into their infrastructure and tactics. The article also offers recommendations for prevention and detection of phishing attacks, emphasizing the importance of MFA, SSO, and continuous vigilance in cybersecurity practices.
Indicators of Compromise (2 / 223 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 9063d16dbc1fb59c9e9e310e4c962fc435c533b9 2024-11-07
FileHash-SHA1 c7244fa49afee3ad28e0014ecbf2a4259bfe4f17 2024-11-07