US-CERT received information from a trusted third-party of a spear phishing campaign using “sign in” themed emails containing malicious links designed to harvest user credentials. According to the trusted third party, suspected intrusion set actors used the "shortme.org" URL shortening service to obfuscate malicious links embedded within emails. The spoofed links appear to be from Yahoo and Gmail email security. The email contains a spoofed unauthorized log-in attempt message to entice the victim to change their password using the embedded link. If successful, the victim will click the link and navigate to the "shortme[.]org" site, hosted at IP address "191.101.31[.]253". The shortened URL would immediately be redirected to a malicious U.S. domain hosted at an unspecified U.S. IP address.
Created: 2026-02-23
Indicatorsは見つかっていない。
このPulseに見つかったCVEはありません。