Post #4060613
2026-07-24 10:40 UTC
❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages.
Here's what we've confirmed so far:
➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS.
➡️ The links carry a hidden payload using a classic technique: an tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript.
➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service.
➡️ Visitors who don't match the target profile get sent to a random Wikipedia article.
➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com.
➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types.
We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form.
🕵️♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected:
➡️ A campaign targeting Dutch recipients from early July, using similar tactics.
➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file.
We're not asserting that they are the same actor, but it's worth watching out for this pattern.
Note, this is early-stage research, and we'll share more as we learn...
#ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam
Replies (0)
No replies.