Elektrine lite

← Feed

@spamhaus@infosec.exchange

Post #4060613

2026-07-24 10:40 UTC

❗We're tracking a spam campaign that abuses cross-site scripting (XSS) flaws in website search forms to funnel victims to phishing and scam pages. Here's what we've confirmed so far: ➡️ Spam emails, mainly from compromised accounts, many on Microsoft 365 (*.onmicrosoft.com), linking to legitimate sites whose search forms are vulnerable to XSS. ➡️ The links carry a hidden payload using a classic technique: an tag pointing to a non-existent file, with the onerror handler carrying the actual JavaScript. ➡️ That script redirects the visitor to a landing site. The landing site itself applies restrictive geo/browser filtering,behavior similar to a traffic distribution system (TDS), but handled by the site itself rather than a separate redirect service. ➡️ Visitors who don't match the target profile get sent to a random Wikipedia article. ➡️ Most landing pages we've seen promote an "AI-powered" investment product, using the .mom TLD - though we've also seen .beauty, .skin, .makeup, .click, and .com. ➡️ We've also observed banking phish delivered through the same mechanism, along with other, less common target types. We're listing the abused (legitimate) sites as abused-legit and notifying operators so they can patch the vulnerable form. 🕵️‍♂️ While digging into this, we found two other threads that use a similar spammer modus operandi, but we haven't yet confirmed if they are connected: ➡️ A campaign targeting Dutch recipients from early July, using similar tactics. ➡️ A separate lure impersonating a Zoom meeting invite, leading to a fake "client update" page that serves a .vbs file. We're not asserting that they are the same actor, but it's worth watching out for this pattern. Note, this is early-stage research, and we'll share more as we learn... #ThreatIntel #XSS #Phishing #InfoSec #Cybercrime #WebSecurity #Scam

Replies (0)

No replies.