logo

013

ID: 9c75b370-cfc9-4e14-94e9-061a34d016c2

STIX ID: report--9c75b370-cfc9-4e14-94e9-061a34d016c2

Threat Score

78/100

Uploaded: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
Positive Technologies reported an active global campaign abusing known Microsoft Exchange Server vulnerabilities to inject JavaScript keyloggers into Outlook authentication pages, harvesting credentials from at least 65 victims in 26 countries; variants either write stolen data to web-accessible files or exfiltrate via Telegram bots and DNS tunnels, and later analysis attributed related activity and follow-on payloads (PhantomDL/PhantomCore) to a named hacking group with thousands of accounts collected.