A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information.
The threat actors are not relying on a single method to trick their victims. Instead, they are utilizing three distinct phishing lures designed to create a false sense of urgency:
The campaign follows a carefully planned attack chain designed to capture user credentials for downstream account takeovers:
The Hook: The victim receives a phishing email, such as a fake “Teams Voice Message” alert, containing a “Listen Now” button.
The Pivot: When the user clicks the link, they are secretly redirected through a tracking domain, specifically skimresources[.]com.
The Payload: The redirect ultimately lands the victim on a highly convincing, pixel-perfect fake login page. These fake pages mimic Microsoft Teams, Xfinity, or UAE Pass.
The Goal: Once the user enters their username and password, attackers harvest the credentials to completely take over the victim’s accounts.
A key feature of this campaign is the abuse of legitimate WordPress websites.
The attackers are hacking into poorly secured sites and hiding their malicious phishing pages deep within standard system folders.
By placing their fake login pages in core directories like /wp-includes/ or /bin/, the attackers can hide in plain sight, avoiding immediate detection by website owners and automated security scanners.
Security teams and network administrators should block the following compromised domains and file paths associated with this campaign:
crsons[.]net/wp-includes/js/tinymce/~crsons[.]net/wp-includes/cgi/UAE%20PASS.htmafghantarin[.]com/afghantarin/admin/waitme/~medinex[.]in/includes/bin/index[.]phpcabinetzeukeng[.]net/config/[.]bin/voicemailrnedinex[.]comTo protect against this threat, organizations should train employees to carefully verify email senders and hover over links before clicking, especially when receiving unexpected voicemails or document alerts.
Additionally, website administrators must ensure their WordPress installations, themes, and plugins are fully updated to prevent their infrastructure from being weaponized.
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…