Tag
high
threat
Operation Fake KickOff: Attackers Abuse Recruiters and SaaS to Harvest Work Credentials
2 rules 9 TTPs 1 IOCO-UNC-038 is conducting a multi-stage Adversary-in-the-Middle (AiTM) phishing operation that abuses legitimate SaaS platforms and recruiter identities to steal corporate Google Workspace credentials and bypass multi-factor authentication.
Google Workspace
O-UNC-038
phishing
credential-theft
aitm
social-engineering
mfa-bypass
saas-abuse
google-workspace
2r
9t
1i
high
advisory
SaaS Notification Pipeline Abuse for Phishing and Spam Campaigns
3 rules 1 TTP 2 IOCsAttackers are abusing notification pipelines in SaaS platforms like GitHub and Jira to deliver phishing and spam emails by exploiting legitimate platform features and bypassing traditional email security measures.
saas-abuse
phishing
credential-harvesting
github
jira
3r
1t
2i