WHOIS API
Phishing Campaign Targeting Microsoft Azure Infrastructure
Pages
9
Time to read
6 mins
Language
English
Pages
9
Time to read
6 mins
Language
English
This report details a phishing campaign identified by Unit 42 of Palo Alto Networks, which targets European companies to compromise their Microsoft Azure cloud infrastructure by harvesting account credentials. The campaign, which peaked in June 2024, utilized the HubSpot Free Form Builder service. The researchers identified 33 indicators of compromise (IoCs), including 16 domains and 17 IP addresses, through their analysis. The report outlines the IoCs and their characteristics, including their registration details and historical IP resolutions. A comprehensive search for connected artifacts revealed 494 additional items linked to the IoCs, including email-connected domains and various IP-connected domains. The report emphasizes the importance of thorough investigations to verify the nature of identified threats, noting that some entities may be misclassified as malicious. The findings are supported by extensive data from WHOIS and DNS queries, providing a detailed view of the phishing landscape associated with this campaign.