[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/ "Business Email Compromise")  
  [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)

# Effective Phishing Campaign Targeting European Companies and Organizations

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 10 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced URL Filtering icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced URL Filtering](https://unit42.paloaltonetworks.com/product-category/advanced-url-filtering/ "Advanced URL Filtering")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex](https://unit42.paloaltonetworks.com/product-category/cortex/ "Cortex")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Cortex XSIAM icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XSIAM](https://unit42.paloaltonetworks.com/product-category/cortex-xsiam/ "Cortex XSIAM")[![Managed Threat Hunting icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Managed Threat Hunting](https://unit42.paloaltonetworks.com/product-category/managed-threat-hunting/ "Managed Threat Hunting")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Shachar Roitman](https://unit42.paloaltonetworks.com/author/shachar-roitman/)
  * [Ohad Benyamin Maimon](https://unit42.paloaltonetworks.com/author/ohad-benyamin-maimon/)
  * [William Gamazo](https://unit42.paloaltonetworks.com/author/william-gamazo/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:December 18, 2024

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Business Email Compromise](https://unit42.paloaltonetworks.com/category/business-email-compromise/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CRM](https://unit42.paloaltonetworks.com/tag/crm/)
  * [Docusign](https://unit42.paloaltonetworks.com/tag/docusign/)
  * [EMEA](https://unit42.paloaltonetworks.com/tag/emea/)
  * [Germany](https://unit42.paloaltonetworks.com/tag/germany/)
  * [HubSpot](https://unit42.paloaltonetworks.com/tag/hubspot/)
  * [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/)
  * [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/)
  * [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/)
  * [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/)
  * [Redirection](https://unit42.paloaltonetworks.com/tag/redirection/)
  * [United Kingdom](https://unit42.paloaltonetworks.com/tag/united-kingdom/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/european-phishing-campaign/?pdf=download&lg=en&_wpnonce=edee969a51 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/european-phishing-campaign/?pdf=print&lg=en&_wpnonce=edee969a51 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Effective%20Phishing%20Campaign%20Targeting%20European%20Companies%20and%20Organizations&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F&title=Effective%20Phishing%20Campaign%20Targeting%20European%20Companies%20and%20Organizations "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F&text=Effective%20Phishing%20Campaign%20Targeting%20European%20Companies%20and%20Organizations "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Effective%20Phishing%20Campaign%20Targeting%20European%20Companies%20and%20Organizations%20https%3A%2F%2Funit42.paloaltonetworks.com%2Feuropean-phishing-campaign%2F "Share in Mastodon")

## **Executive Summary**

Unit 42 researchers recently investigated a phishing campaign targeting European companies, including in Germany and the UK. Our investigation revealed that the campaign aimed to harvest account credentials and take over the victim's Microsoft Azure cloud infrastructure.

The campaign's phishing attempts peaked in June 2024, with fake forms created using the HubSpot Free Form Builder service. Our telemetry indicates the threat actor successfully targeted roughly 20,000 users across various European companies.

Our investigation revealed that while the campaign appears to have begun in June 2024, the phishing campaign was still active as of September 2024. The campaign targeted European companies in the following industries:

* Automotive
* Chemical
* Industrial compound manufacturing

Palo Alto Networks customers are better protected from the threats discussed in this article through the following products and services:

* [Advanced WildFire](https://docs.paloaltonetworks.com/wildfire)
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/dns-security)
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/resources/datasheets/cortex-xsiam-aag)
* [Unit 42 Managed Services Team](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response)

If you think you might have been compromised or have an urgent matter, contact the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html).

| **Related Unit 42 Topics** | [**Phishing**](https://unit42.paloaltonetworks.com/category/business-email-compromise/), **[Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/)** , **[Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/)** |
|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|

## **The Phishing Operation**

In June 2024, Unit 42 researchers identified a phishing campaign targeting at least 20,000 European automotive, chemical and industrial compound manufacturing users. The phishing emails contained either an attached Docusign-enabled PDF file or an embedded HTML link directing victims to malicious HubSpot [Free Form Builder](https://www.hubspot.com/products/marketing/forms) links embedded within phishing emails. HubSpot is a cloud-based customer relationship management (CRM), marketing, sales and content management system (CMS) operation platform.

Working with HubSpot security teams, we determined that HubSpot was not compromised during this phishing campaign, nor were the Free Form Builder links delivered to target victims via HubSpot infrastructure.

We reached out to Docusign and they responded with, "The trust, security and privacy of our customers has always been at the core of Docusign's business. Since the time of this investigation, Docusign has implemented a number of additional actions to strengthen our proactive preventative measures, which --- to date --- have significantly decreased the number of signers receiving fraudulent Docusign signature requests."

Figure 1 shows a simplified diagram of the phishing operation. Attackers sometimes used two levels of redirection to reach their credential harvesting infrastructure.
![Flowchart depicting an email phishing tactic using a fake document prompt leading to a fraudulent Outlook Web App login page, followed by credential harvesting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-562330-137925-1.png) Figure 1. Phishing operation flow.

Evidence showed that the threat actor targeted several phishing attempts toward specific organizations. These phishing attempts came complete with thematic dialogue specific to that organization's brand and email address formatting.

Several malicious PDF attachments used the target organization's name in the file name, (i.e., CompanyName.pdf). Figure 2 shows an example of a malicious PDF file mimicking a Docusign document.
![Screenshot of an email notification from DocuSign stating "You have a new document to review and sign." The email includes a "View Document" button and a disclaimer about the security and confidentiality of the electronic document signing process. Instructions and contact support information are also provided.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-565324-137925-2.png) Figure 2. Phishing lure theme.

Clicking "View Document" would redirect the victim to a Free Form with the following URL format: https://share-eu1.hsforms\[.\]com/FORM-ID.

Figure 3 shows an example of a phishing attempt with embedded HTML.
![Screenshot of an email notification from DocuSign informing the recipient that a document is ready to view and sign.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-568409-137925-3.png) Figure 3. Phishing embedded HTML.

Both the malicious PDF and HTML examples led victims to the Free Form window shown in Figure 4 if they clicked through.
![Screenshot of an online form asking if the user is authorized to view and download a sensitive company document, with options 'Yes' and 'No.' Below is a button labeled 'View Document On Microsoft Secured Cloud' and a link to 'Create your own free form to generate leads from your website.'](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-571746-137925-4.png) Figure 4. HubSpot Free Form.

The wording in the Free Form window "View Document on Microsoft Secured Cloud" indicates that the phishing campaign is also targeting Microsoft accounts. We verified that the phishing campaign did make several attempts to connect to the victim's Microsoft Azure cloud infrastructure.

Once the user clicked "View Document on Microsoft Secured Cloud," they were redirected to the threat actor's credential harvesting pages. This page prompted the victim to supply their login information for Microsoft Azure.

We also found evidence that this phishing campaign targeted users of European organizations. Figure 5 below is an example of a phishing website designed to target notaries in France.
![Screen capture displaying a notification with a message in French. There are options to enter an email address, connect to view a PDF, and a continue button.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-574950-137925-5.png) Figure 5. Phishing targeting notary offices.

Although this phishing setup differs from the one we mentioned previously, we found the attackers reused the same infrastructure. This infrastructure included the registered first-level domain, which we'll describe in more detail in a later [section](#post-137925-_qhpzm74zv59z).

A list of the Free Form URLs identified during this investigation is included in the [Indicators of Compromise](#post-137925-_8m9p75m3jvm9) section of this article.

## **Identifying Suspicious Phishing Emails**

By analyzing the phishing emails, we found two indicators helpful to identify similar attacks. One was a tone of urgency, and the other was failing its authentication checks.

Both of these are well-known phishing indicators, but due to their importance, we have summarized each.

* Tone of urgency:
  * Phishing emails often create urgency with phrases like "immediate action required" to pressure quick responses
* Failed authentication checks:
  * A "Fail" outcome for the Sender Policy Framework (SPF) means the sender's IP address is unauthorized to send emails on behalf of the domain, suggesting possible spoofing
  * A "Fail" outcome for DomainKeys Identified Mail (DKIM) indicates the email's digital signature was not verified, implying it could have been altered or forged
  * A "Temporary Error" for Domain-based Message Authentication, Reporting and Conformance (DMARC) points to a short-term issue with domain alignment, often due to server or DNS delays, weakening domain authentication.

Note: DMARC relies on successful SPF and DKIM checks to confirm domain legitimacy, providing protection against spoofing and phishing.

In the snippet below, from the original mail attribute, we can see the suspicious indicators mentioned above.  
"Subject": "Completion Required XXXXXXXXX ", "AuthDetails": \[ { "Name": "SPF", "Value": "Fail" }, { "Name": "DKIM", "Value": "Fail" }, { "Name": "DMARC", "Value": "Temporary error" }, \],

|-------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 | "Subject": "Completion Required XXXXXXXXX ", "AuthDetails": \[ { "Name": "SPF", "Value": "Fail" }, { "Name": "DKIM", "Value": "Fail" }, { "Name": "DMARC", "Value": "Temporary error" }, \], |

**Initial Access and Evasion Techniques**

Adding their device to the authentication process allowed the threat actor to make their logins appear to come from a trusted device. By using VPN proxies, the threat actor's login attempts originated from the same country as the victim organization. However, Figure 6 shows that there were instances of login attempts from previously blocked regions.
![Cortex XDR screenshot showing an alert. Below the alert is a table containing columns for time, vendor, product, severity, integrity, and success, with specific values listed in each cell.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-577769-137925-6.png) Figure 6. Impossible traveler - SSO alert information

Figure 7 provides an example of an alerting event in Cortex. These alerts identify login events from uncommon or suspicious sources.
![Screenshot of a Cortex XDR alert description window showing a security notification. It lists login attempt details from four countries: Netherlands, Germany, United Kingdom, and an rare country: The Netherlands. It includes successful and failed login attempt numbers, and mentions authentication through a managed ASN, possibly an organizational VPN or proxy. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-581265-137925-7.png) Figure 7. Impossible traveler - SSO alert details.

We also identified the use of a new Autonomous System Number (ASN) that had not been seen in prior user activity. This added another layer of suspicion. Figure 8 shows another example of an alerting event that can notify security teams of malicious login attempts.
![A Cortex XDR screenshot displaying an interface with various details listed, such as 'First successful SSO access from ASN in the organization.' On the right side, there are flowchart elements with question marks and a red alert icon, showing a process or notification regarding user access and authentication. Some identifying information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-584356-137925-8.png) Figure 8. First SSO access from ASN in organization alert details.

Finally, the threat actor employed unusual user-agent strings during their connection attempts to the victim systems. An example of this custom user-agent string from the phishing campaign was as follows:  
Client=OWA;Action=ViaProxy

|---|----------------------------|
| 1 | Client=OWA;Action=ViaProxy |

## **The Phishing Redirection**

During the investigation, we identified at least 17 working Free Forms used to redirect victims to different threat actor-controlled domains. The majority of the identified domains were hosted at the top-level domain .buzz. Each of the identified Free Forms contained a similar Microsoft Outlook Web App landing page design and redirection pattern, shown in Figure 9.
![Screenshot of a spoofed Outlook Web App login page, featuring fields for Email address and Password with a Sign In button, and the Microsoft logo at the bottom, set against a blue background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-587941-137925-9.png) Figure 9. Malicious Microsoft Outlook Web App landing page.

At the time of our investigation, the majority of the servers we identified that were hosting phishing content used by the threat actor were offline. However, we did find that two of these host servers were active, allowing us to collect the phishing page source code. Both of the phishing source code samples that we captured had the same structure.

The phishing code used a Base64-encoded URL designed for credential harvesting and redirecting the victims to a Microsoft Outlook Web Access (OWA) login page. Figure 10 shows a screenshot of the source code from the phishing page.
![Screen capture showing a section of code in an IDE. The code includes functions and is layered in two overlapping screenshots.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-590931-137925-10.png) Figure 10. Microsoft OWA login page source code.

The sample source code revealed that the phishing links led victims to websites using a URL that simulated the target victim organization's name. The phishing websites presented to the victim included their organization's name followed by the top-level domain .buzz (i.e., http\[:\]//www.acmeinc\[.\]buzz):

* hxxps://\<victim\>.buzz/doc0024/index.php
* hxxps://\<victim\>.buzz/2doc5/index.php

## **The Phishing Infrastructure**

The phishing campaign was hosted across various services, including Bulletproof VPS hosts. This is a hosting service known for providing a high degree of anonymity, lax enforcement of legal regulations and resistance to being shut down. They are often associated with malicious operations, including phishing operations.

One of the more interesting findings for us was the infrastructure clusters we analyzed, from the compromised and targeted users we identified. By analyzing telemetry collected from the victims, we found that the threat actor used the same hosting infrastructure for multiple targeted phishing operations. They also used this infrastructure for accessing compromised Microsoft Azure tenants during the account takeover operation.

Figure 11 shows an example of such a cluster. The top line of the diagram, the user layer, is indicated with the number 1. The victims are anonymized so as not to identify the targeted and compromised users.
![Network diagram showing connections between entities such as Microsoft, HubSpot, and various nodes. The diagram includes different layers like User, Domain, and Hosting/Access, illustrating paths and relationships in a cybersecurity analysis context.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-593909-137925-11.png) Figure 11. Threat actor's infrastructure analysis diagram.

According to our telemetry, User A was compromised, resulting in their Microsoft Azure tenant credentials also being exposed. Connections labeled with the word access and indicated with the number 2 revealed that the threat actor used the same phishing hosting infrastructure for network connection access to the compromised user's system.

The same infrastructure being used for both the phishing hosting infrastructure as well as the direct connection to the victim environments suggests that the threat actor owned the hosted server instead of renting or subscribing to a shared "hosting" service.

The website forklog\[.\]com, indicated by the number 3 in the diagram, is an online publication presented in both Russian and Ukrainian languages. The contents of the publication focus on cryptocurrencies and blockchain technologies. This domain was used by the threat actors within one of their victim's environments and points to a potential means of future victim targeting or income generation.

We also found the compromised company associated with User A had a publicly exposed control panel associated with a web hosting platform used to run and automate cloud-based applications.

We found that the threat actor consistently scanned the control panel from the same phishing infrastructure that deployed the phishing campaign redirection hosts. We did not identify any successful attempts to access the control panel.

## **Persistence**

During the account takeover, the threat actor added a new device to the victim's account. This allowed persistent access to the account, even as security efforts were made to lock them out. Figure 12 displays an alert of suspicious resource creation within the Microsoft Azure tenant.
![Screenshot of the Cortex XDR interface showing an alert for a suspicious authentication method. The screen displays various fields including Alert Description, Severity Level, and Activity Details, with graphical elements like sliders and icons for settings and alerts. Some information has been redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-598104-137925-12.png) Figure 12. Suspicious method addition to Azure account alert details.

When IT regained control of the account, the attacker immediately initiated a password reset, attempting to regain control. This created a tug-of-war scenario in which both parties struggled for control over the account. This resulted in several additional alerts being triggered within the organization, shown in Figure 13.
![A screenshot of the Cortex XDR interface showing a security alert from Azure AD. The interface includes various tabs and sections such as Information Details, Alert Context, and Activity Timeline, along with graphical elements like sliders and icons, in a monochromatic color scheme. Some information is redacted.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/12/word-image-601036-137925-13.png) Figure 13. Azure Active Directory account unlock/successful password reset alert details.

## Conclusion

In this article, we reviewed a phishing campaign that targeted European companies, including German and UK automakers and chemical manufacturing organizations. Threat actors directed the phishing campaign to target the victim's Microsoft Azure cloud infrastructure via credential harvesting attacks on the phishing victim's endpoint computer. They then followed this activity with lateral movement operations to the cloud.

The campaign's phishing operation, which leveraged HubSpot Free Form builder services, peaked in June 2024. We believe the threat actor successfully compromised multiple victims in different companies across the targeted countries.

Unit 42 researchers have an open dialogue with HubSpot in relation to the phishing operations leveraging their services and have worked with them to develop notifications and mitigation strategies. We have also worked with the compromised organizations to ensure they have the resources they need to recover from the phishing operation.

**Detection and Mitigations**

For Palo Alto Networks customers, our products and services provide the following coverage associated with this group:

* [Advanced WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) cloud-delivered malware analysis service accurately identifies the known samples as malicious.
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) identify domains associated with this group as malicious.
* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [XSIAM](https://www.paloaltonetworks.com/resources/datasheets/cortex-xsiam-aag) detect user and credential-based threats by analyzing user activity from multiple data sources including endpoints, network firewalls, Active Directory, identity and access management solutions, and cloud workloads. Cortex builds behavioral profiles of user activity over time with machine learning. By comparing new activity to past activity, peer activity and the expected behavior of the entity, Cortex detects anomalous activity indicative of credential-based attacks.
* [Unit 42 Managed Detection and Response Service](https://www.paloaltonetworks.com/resources/datasheets/unit42-managed-detection-and-response) delivers continuous 24/7 threat detection, investigation and response/remediation to customers of all sizes globally.

If you think you may have been compromised or have an urgent matter, get in touch with the [Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

Palo Alto Networks has shared these findings, including file samples and indicators of compromise, with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the [Cyber Threat Alliance](https://www.cyberthreatalliance.org/).

## Appendix

### MITRE Techniques

|                                                                                                         **Alert Name**                                                                                                         |                **Alert Source**                |                                      **ATT\&CK Technique**                                       |
|              [**First SSO access from ASN in organization**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-Alert-name/First-SSO-access-from-ASN-in-organization)               |   **XDR Analytics BIOC, Identity Analytics**   | [**Valid Accounts: Domain Accounts (T1078.002)**](https://attack.mitre.org/techniques/T1078/002) |
|        [**First connection from a country in organization**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-Alert-name/First-connection-from-a-country-in-organization)         |   **XDR Analytics BIOC, Identity Analytics**   |           [**Compromise Accounts (T1586)**](https://attack.mitre.org/techniques/T1586)           |
|                               [**Impossible traveler - SSO**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Analytics-Alert-Reference-by-Alert-name/Impossible-traveler-SSO)                                | **XDR** **Analytics** **, Identity Analytics** |           [**Compromise Accounts (T1586)**](https://attack.mitre.org/techniques/T1586)           |
| [**Suspicious authentication method addition to Azure account**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Analytics-Alert-Reference-by-Alert-name/Authentication-method-added-to-an-Azure-account) | **XDR** **Analytics** **, Identity Analytics** |               [**Persistence (TA0003)**](https://attack.mitre.org/tactics/TA0003/)               |
|       [**Azure AD account unlock/password reset attempt**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Analytics-Alert-Reference-by-Alert-name/Azure-AD-account-unlock/password-reset-attempt)        |   **XDR Analytics BIOC, Identity Analytics**   |               [**Persistence (TA0003)**](https://attack.mitre.org/tactics/TA0003/)               |
|                         [**SSO with abnormal user agent**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Analytics-Alert-Reference-by-Alert-name/SSO-with-abnormal-user-agent)                          |   **XDR Analytics BIOC, Identity Analytics**   |             [**Initial Access (TA0001)**](https://attack.mitre.org/tactics/TA0001/)              |
|              [**Abnormal Communication to a Rare Domain**](https://docs-cortex.paloaltonetworks.com/r/Cortex-XSIAM/Cortex-XSIAM-Analytics-Alert-Reference-by-Alert-name/Abnormal-Communication-to-a-Rare-Domain)               |   **XDR Analytics BIOC, Network Analytics**    |           [**Command and Control (TA0011)**](https://attack.mitre.org/tactics/TA0011)            |
|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------|--------------------------------------------------------------------------------------------------|

## Indicators of Compromise

### **HubSpot Free Form URL Links**

* hxxps://share-eu1.hsforms\[.\]com/1P\_6IFHnbRriC\_DG56YzVhw2dz72l
* hxxps://share-eu1.hsforms\[.\]com/1UgPJ18suRU-NEpmYkEwteg2ec0io
* hxxps://share-eu1.hsforms\[.\]com/12-j0Y4sfQh-4pEV6VKVOeg2dzmbq
* hxxps://share-eu1.hsforms\[.\]com/1cJJXJ0NfTPOKwn23oAmmzQ2e901x
* hxxps://share-eu1.hsforms\[.\]com/1wg25r1Z-R5GkhY6k-xGzOg2dvcv5
* hxxps://share-eu1.hsforms\[.\]com/1G-NQN9DbSVmDy1HDeovJCQ2ebgc6
* hxxps://share-eu1.hsforms\[.\]com/1AEc2-gS4TuyQyAiMQfB5Qw2e5xq0
* hxxp://share-eu1.hsforms\[.\]com/1wg25r1Z-R5GkhY6k-xGzOg2dvcv5
* hxxps://share-eu1.hsforms\[.\]com/1zP2KsosARaGzLqdj2Umk6Q2ekgty
* hxxps://share-eu1.hsforms\[.\]com/1fnJ8gX6kR\_aa5HlRyJhuGw2ec8i2
* hxxps://share-eu1.hsforms\[.\]com/1QPAfZcocSuu3AnqznjU14A2eabj0
* hxxps://share-eu1.hsforms\[.\]com/176T8k3N9Q562OEEfhS22Fg2ebzvj
* hxxps://share-eu1.hsforms\[.\]com/18wO3Zb9hTIuittmhHvQFuQ2ec8gt
* hxxps://share-eu1.hsforms\[.\]com/1vNr8tB1GS4mZuYg81ji3dg2e08a3
* hxxps://share-eu1.hsforms\[.\]com/1qe8ypRpdTr284rkNpgmoow2ebzty
* hxxps://share-eu1.hsforms\[.\]com/1C1IZ0\_b-SD6YXS66alL4EA2e90m9

### **Phishing Infrastructure URLs - Level 1**

* hxxps://technicaldevelopment.industrialization\[.\]buzz/?o0B=RLNT
* hxxps://vigaspino\[.\]com/2doc5/index.php?submissionGuid=1d51a08d-cf55-4146-8b5b-22caa765ac85
* hxxps://technicaldevelopment.rljaccommodationstrust\[.\]buzz/?WKg=2Ljv8
* hxxps://purchaseorder.vermeernigeria\[.\]buzz/?cKg=C3\&submissionGuid=4631b0c9-5e10-4d81-b1d6-4d01045907e7
* hxxps://asdrfghjk3wr4e5yr6uyjhgb.mhp-hotels\[.\]buzz/?Nhv3zM=xI7Kyf
* hxxps://purchaseorder.europeanfreightleaders\[.\]buzz/?Mt=zqoE\&submissionGuid=476f32d0-e667-4a18-830b-f57a2b401fc3
* hxxps://orderspecification.tekfenconstruction\[.\]buzz/?6BI=AmaPH\&submissionGuid=e2ce33ea-ee47-4829-882c-592217dea521
* hxxps://asdrfghjk3wr4e5yr6uyjhgb.mhp-hotels\[.\]buzz/?Nhv3zM=xI7Kyf
* hxxps://d2715zbmeirdja.cloudfront\[.\]net/?\_\_hstc=251652889.fcaff35c15872a69c6757196acd79173.1727206111338.1727206111338.1727206111338.1\&\_\_hssc=251652889.158.1727206111338\&\_\_hsfp=1134454612\&submissionGuid=30359eaf-a821-472d-ba17-dd2bd0d96b96
* hxxps://docusharepoint.fundament-advisory\[.\]buzz/?3aGw=Nl9
* hxxps://wr43wer3ee.cyptech\[.\]com\[.\]au/oeeo4/ewi9ew/mnph\_term=?/\&submissionGuid=50aa078a-fb48-4fec-86df-29f40a680602
* hxxp://orderconfirmation.dgpropertyconsultants\[.\]buzz/
* hxxps://espersonal\[.\]org/doc0024/index.php?submissionGuid=6e59d483-9dc2-48f8-ad5a-c2d2ec8f4569
* hxxps://vigaspino\[.\]com/2doc5/index.php?submissionGuid=093410a5-c228-4ddf-890c-861cdc6fe5d8
* hxxps://technicaldevelopment.industrialization\[.\]buzz/?o0B=RLNT
* hxxps://espersonal\[.\]org/doc0024/index.php?submissionGuid=96a9b82a-55d3-402d-9af4-c2c5361daf5c
* hxxps://orderconfirmating.symmetric\[.\]buzz/?df=ZUvkMN\&submissionGuid=e06a1f83-c24e-4106-b415-d2f43a06a048

### **Phishing Infrastructure URLs - Level 2**

* hxxps://docs.doc2rprevn\[.\]buzz?username=
* hxxps://docusharepoint.fundament-advisory\[.\]buzz/?3aGw=Nl9
* hxxps://9qe.daginvusc\[.\]com/miUxeH/
* hxxps://docs.doc2rprevn\[.\]buzz/?username=
* hxxps://vomc.qeanonsop\[.\]xyz/?hh5=IY\&username=ian@deloitte.es
* hxxps://sensational-valkyrie-686c5f.netlify\[.\]app/?e=

### **IP Addresses**

* 167\.114.27\[.\]228
* 144\.217.158\[.\]133
* 208\.115.208\[.\]118
* 13\.40.68\[.\]32
* 18\.67.38\[.\]155
* 91\.92.245\[.\]39
* 91\.92.244\[.\]131
* 91\.92.253\[.\]66
* 94\.156.71\[.\]208
* 91\.92.242\[.\]68
* 91\.92.253\[.\]66
* 188\.166.3\[.\]116
* 104\.21.25\[.\]8
* 172\.67.221\[.\]137
* 49\.12.110\[.\]250
* 74\.119.239\[.\]234
* 208\.91.198\[.\]96
* 94\.46.246\[.\]46

### **PDFs**

* (Zoomtan.pdf) b2ca9c6859598255cd92700de1c217a595adb93093a43995c8bb7af94974f067
* (Belzona.pdf) f3f0bf362f7313d87fcfefcd6a80ab0f18bc6c5517d047be186f7b81a979ff91
* (Pcc.pdf) deff0a6fbf88428ddef2ee3c4d857697d341c35110e4c1208717d9cce1897a21

## **XDR Queries**

Cortex XDR queries to detect the presence of the operations explained within the article can be found in the [link on our GitHub](https://github.com/PaloAltoNetworks/Unit42-Threat-Intelligence-Article-Information/blob/main/Effective-Phishing-Campaign-Targeting-European-Companies-and-Institutions-Cortex-XDR-Queries.txt).

### Points To Consider During Remediation

* Microsoft Entra ID consideration:
  * Ensure that any compromised user's Microsoft Entra ID account is disabled until any ongoing investigation and eradication operations are completed.
* Revoke users' session:
  * When marking a user as compromised in Azure Entra ID, using the "revoke sessions" function, be aware that this action will not terminate active sessions.
  * Revoking sessions will only invalidate the Primary Refresh Token, allowing the threat actor to maintain access until their current Access Token expires, typically within 60-90 minutes.
  * While you should still mark the user as compromised and revoke sessions to prevent new access tokens from being issued, consider implementing Continuous Access Evaluation to address this limitation and enhance security by allowing real-time session management.
* Disable "Self-Service Tenant Creation":
  * This feature enables internal users to create a new tenant, which threat actors may exploit to exfiltrate data.

*Updated Dec. 19, 2024, at 10:25 a.m. PT to clarify verbiage.*
Back to top

### Tags

* [CRM](https://unit42.paloaltonetworks.com/tag/crm/ "CRM")
* [Docusign](https://unit42.paloaltonetworks.com/tag/docusign/ "Docusign")
* [EMEA](https://unit42.paloaltonetworks.com/tag/emea/ "EMEA")
* [Germany](https://unit42.paloaltonetworks.com/tag/germany/ "Germany")
* [HubSpot](https://unit42.paloaltonetworks.com/tag/hubspot/ "HubSpot")
* [Malicious Domains](https://unit42.paloaltonetworks.com/tag/malicious-domains/ "Malicious Domains")
* [Manufacturing](https://unit42.paloaltonetworks.com/tag/manufacturing/ "Manufacturing")
* [Microsoft Azure](https://unit42.paloaltonetworks.com/tag/microsoft-azure/ "Microsoft Azure")
* [MITRE](https://unit42.paloaltonetworks.com/tag/mitre/ "MITRE")
* [Redirection](https://unit42.paloaltonetworks.com/tag/redirection/ "Redirection")
* [United Kingdom](https://unit42.paloaltonetworks.com/tag/united-kingdom/ "United Kingdom")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: LDAP Enumeration: Unveiling the Double-Edged Sword of Active Directory](https://unit42.paloaltonetworks.com/lightweight-directory-access-protocol-based-attacks/ "LDAP Enumeration: Unveiling the Double-Edged Sword of Active Directory")

### Table of Contents

* 

### Related Articles

* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration](https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/ "article - table of contents")
* [Paved With Intent: ROADtools and Nation-State Tactics in the Cloud](https://unit42.paloaltonetworks.com/roadtools-cloud-attacks/ "article - table of contents")

## Related Business Email Compromise Resources

![Pictorial representation of a group of individuals discussing an idea with a whiteboard.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/02_Listicle_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) February 3, 2026 [#### Why Smart People Fall For Phishing Attacks](https://unit42.paloaltonetworks.com/psychology-of-phishing/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/psychology-of-phishing/ "Why Smart People Fall For Phishing Attacks")  
  ![Pictorial representation of a IUAM ClickFix generator. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen, indicating malware.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/03_Malware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) October 8, 2025 [#### The ClickFix Factory: First Exposure of IUAM ClickFix Generator](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")

* [Phishing Kit](https://unit42.paloaltonetworks.com/tag/phishing-kit/ "Phishing Kit")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/clickfix-generator-first-of-its-kind/ "The ClickFix Factory: First Exposure of IUAM ClickFix Generator")  
  ![Pictorial representation of phishing bait using AI. A luminous cube labeled "AI" centrally placed on a futuristic circuit board landscape with glowing blue lights and connections.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/03_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 19, 2025 [#### Fashionable Phishing Bait: GenAI on the Hook](https://unit42.paloaltonetworks.com/genai-phishing-bait/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/genai-phishing-bait/ "Fashionable Phishing Bait: GenAI on the Hook")  
  ![Pictorial representation of social engineering. Digital illustration of four human profiles connected by glowing neural network lines against a dark background, symbolizing connectivity and technology.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/cover-1920x900-no-blades-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) July 30, 2025 [#### 2025 Unit 42 Global Incident Response Report: Social Engineering Edition](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/)

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ClickFix](https://unit42.paloaltonetworks.com/tag/clickfix/ "ClickFix")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/ "2025 Unit 42 Global Incident Response Report: Social Engineering Edition")  
  ![Pictorial representation of homograph attacks. 3D illustration of an open laptop displaying an envelope icon on the screen, accompanied by a smartphone and tablet, all set against a dark background with neon lighting.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/01_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 25, 2025 [#### The Ηоmоgraph Illusion: Not Everything Is As It Seems](https://unit42.paloaltonetworks.com/homograph-attacks/)

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/homograph-attacks/ "The Ηоmоgraph Illusion: Not Everything Is As It Seems")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![Pictorial representation of a QR code phishing campaign. Digital artwork of a futuristic, glowing shield disintegrating into small particles, set against a dark blue, speckled background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/03/09_Business_email_compromise_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 1, 2025 [#### Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon](https://unit42.paloaltonetworks.com/qr-code-phishing/)

* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")

* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/qr-code-phishing/ "Evolution of Sophisticated Phishing Tactics: The QR Code Phenomenon")  
  ![An Asian woman examining data on multiple computer screens in a high-tech digital environment, surrounded by visual representations of data and code. Lens flare is prominent across the image.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/02/07_Cloud_cybersecurity_research_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) February 28, 2025 [#### JavaGhost's Persistent Phishing Attacks From the Cloud](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/)

* [AWS](https://unit42.paloaltonetworks.com/tag/aws/ "AWS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/javaghost-cloud-phishing/ "JavaGhost’s Persistent Phishing Attacks From the Cloud")  
  ![A pictorial representation of a campaign like BeaverTail. Digital globe with interconnected network lines and data streams on a futuristic interface, symbolizing global connectivity and information technology advancements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/01_Nation-State-cyberattacks_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) November 14, 2024 [#### Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Lazarus](https://unit42.paloaltonetworks.com/tag/lazarus/ "Lazarus")

* [BeaverTail](https://unit42.paloaltonetworks.com/tag/beavertail/ "BeaverTail")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/fake-north-korean-it-worker-activity-cluster/ "Fake North Korean IT Worker Linked to BeaverTail Video Conference App Phishing Attack")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
