Posts

Showing posts with the label #GreeenSpot

GreenSpot APT phishing campaigns with fake 163.com login analysis

Image
  Summary From the Hunt.io blog, I noted that GreenSpot APT phishing campaigns quickly traced the event and downloaded the files to do simple checking.   Technical analysis   Until 2025.2.13, the following sites are still accessible. The fake site hxxp[:]//mail.eco163[.]com/ jumps to hxxps[:]//www.kaola[.]com/ when entering a username. About both hxxps[:]//l2024163[.]com/ and hxxps[:]//chamber.icu/, Potential victims are prompted to enter the username and password twice to download the file. The first try always triggers an error message; its motivation is to let 163[.]com users confirm password accuracy, so the fake sites try to steal valid user credentials. Figure1- Download Large Attachments Figure2- Fake login   To check The attachments out, not finding “VBA Macros” embedded, is high confidence to ensure those without any malicious behavior. It seems that GreenSpot is focused on stealing user credentials, not directly doing harm to the user o...