Researchers Warn of Global Surge in Fake Shipment Tracking Scams
ATT&CK techniques detected
T1566.002Spearphishing Link
90%
"about ongoing phishing attempts abusing their brands - strengthen official domains using strong authentication and domain security protocols such as dmarc, skim and spf to reduce emails sent under the company name - employ a brand protection service that can actively track fake d…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1566.002Spearphishing Link
86%
"been definitively linked to these schemes, the group - ib researchers observed that many of the phishing sites share infrastructure and characteristics commonly associated with darcula. darcula phishkit is a chinese - language phaas platform that emerged in 2023 and has been used…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1566.002Spearphishing Link
82%
". ] top ) they also abuse trusted extensions like. com through lookalike variations designed to mimic real brands. a typical fake shipment tracking scam campaign starts with an attacker setting up a phishing domain and a fake website. next, they typically use one of the following…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1598.003Spearphishing Link
43%
". ] top ) they also abuse trusted extensions like. com through lookalike variations designed to mimic real brands. a typical fake shipment tracking scam campaign starts with an attacker setting up a phishing domain and a fake website. next, they typically use one of the following…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Summary
Some of these campaigns are linked to Darcula, a Chinese-language phishing-as-a-service platform