Cyber Security News

Hackers Targeting HubSpot Users in Targeted Phishing Attack

An active phishing campaign is currently targeting HubSpot users through a sophisticated combination of social engineering and infrastructure compromise.

The attack leverages business email compromise tactics, paired with website hijacking, to deliver credential-stealing malware to unsuspecting marketing professionals and business teams that rely on the platform.

The campaign begins with carefully crafted phishing emails that appear to come from legitimate business accounts.

These messages urge recipients to log into their HubSpot accounts to review marketing campaigns, citing an unusual spike in unsubscribes as the reason for immediate action.

The emails use MailChimp, a trusted email marketing platform, to distribute the attack at scale, ensuring messages pass through secure email gateways because of the platform’s reputation.

Evalian researchers noted that phishing emails use a deceptive technique: embedding malicious URLs in the sender’s display name rather than in the email body.

This approach successfully bypasses many email security controls, which typically scan message content but overlook the sender field.

Phishing Email (Source – Evalian)

Combined with the compromised legitimate business domain, the emails appear authentic to both automated systems and human readers.

Once victims click the embedded URL, they are redirected from a compromised website to a convincing fake HubSpot login portal hosted on Proton66 OOO infrastructure, a Russian bulletproof hosting provider linked to ASN AS 198953.

When users enter their credentials, the login information is transmitted to a login.php file and captured by attackers.

Malicious HubSpot Login Page (Source – Evalian)

The phishing email structure and the replica login page are designed to mirror HubSpot’s legitimate interface.

Hosting infrastructure

The infection mechanism relies on harvesting valid user credentials rather than delivering traditional malware.

Evalian analysts identified that the hosting infrastructure uses a Plesk-managed virtual private server with exposed mail services, including Postfix and Dovecot.

The IP address 193.143.1.220 reveals an unusually broad range of open ports, including SMTP services on ports 25 and 465, IMAP on ports 143 and 993, and multiple Plesk administrative interfaces.

This configuration is typical of infrastructure designed for rapid deployment and rotation of phishing campaigns.

Infrastructure analysis confirmed that the IP is associated with multiple other phishing attempts, indicating a pattern of organized attack activity.

The exposed Plesk control panels allow attackers to quickly deploy new phishing pages, manage compromised email accounts, and rotate infrastructure to evade detection.

Organizations must implement layered security measures that extend beyond standard email authentication protocols to protect against evolving threats.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago