PULSE NAME
Server-Side Phishing: How Credential Theft Campaigns Are Hiding in Plain Sight
WHITE AlienVault 2025-04-15 Modified: 2025-05-15
15
IOCs
MEDIUM VOLUME
This analysis explores an ongoing phishing campaign targeting employee and member portals using a PHP-based phishing kit. The campaign has evolved from using client-side redirects to server-side credential validation, making detection more challenging. Multiple domains impersonating corporate login portals were identified, hosted on infrastructure linked to Chang Way Technologies Co. Limited. The phishing pages employ sophisticated tactics, including two-factor authentication bypasses and decoy content. The campaign's infrastructure and techniques suggest a persistent, possibly state-linked threat actor adapting their methods to evade detection and maintain access to enterprise environments.
Indicators of Compromise (15)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain afilachokloginochok.com 2025-04-15
domain afiocksignoned.com 2025-04-15
domain attdomhomepage.com 2025-04-15
domain charterssonidp.com 2025-04-15
domain empnohourstodayhr.com 2025-04-15
domain eservicesa.live 2025-04-15
domain flyungtogether.com 2025-04-15
domain forurbestexper.com 2025-04-15
domain franchehub.us 2025-04-15
domain hignmarkedmemb.com 2025-04-15
domain ipafranchest.com 2025-04-15
domain lawpaymentpw.live 2025-04-15
domain middafitich.com 2025-04-15
domain myinfoaramapay.com 2025-04-15
domain myportalbsbsist.com 2025-04-15