Sogolytics email notification hijack
Hox rating: ★★✩✩
Threat type: Bulk phishing
Payload: Malicious link
Region: Global
Analyst: Reetta Sainio
Date: 17.05.2023
In this phishing email, attackers manipulate legitimate email notifications from Sogolytics, an online survey tool. These emails disguise themselves as notifications about newly received voicemails.

While all the links in the email appear legitimate, directing users back to the Sogolytics service, the content they deliver is malicious.
Acerta internal service impersonation
Hox rating: ★★✩✩
Threat type: Advanced campaign
Payload: Malicious link
Region: Europe
Analyst: Suvi Hakala
Date: 19.05.2023
This phishing email attempts to impersonate the HR service Acerta. It claims two-factor verification will soon be mandatory for the service and asks the user to register via the provided link.
![acerta TVeestal%Verificatie wordt binnenkort Vanaf I juni 2023 zal ook Acerta de tweestapsverificatie gaan verplichten. Door het instellen van tweestapsverificatle voegt u een extia beveiligingslaag toe aan uw account. Acerta vindt dat uw veiligheid van grmt belang is en daarom voeren ui] deze nieuwe regel dcxvr. Wat moet u doen? Registreer uw tweestapsverificatie via de onderstaande link. Z,O'g dat u tijd bent met registreren, zoals eerder vermeld is de tweestapsverificatie verplicht. de volgt de identificMiemiddelen (elDASi en de IC,DPR) 2023](https://assets-global.website-files.com/6130a9118b1be9aebe2c2837/64a66490f939dd7ec6e7dc8d_Week20-1.png)
A sense of urgency is created with a short deadline and the risk of losing access to HR services.
Microsoft Teams internal service impersonation
Hox rating: ★★★✩
Threat type: Advanced campaign
Payload: Malicious link
Region: Global
Analyst: Minna Herlevi
Date: 19.05.2023
This phishing email is designed to look like it's a Microsoft Teams notification.

The email notifies the victim that they have received a voice message on a fake Microsoft Teams service called ‘Microsoft Audio Teams’. The email is sent from a compromised email address.
Admin support phishing message
Hox rating: ★✩✩✩
Threat type: Bulk phishing
Payload: Malicious link
Region: Global
Analyst: Julia Kylmälä
Date: 19.05.2023
This email is designed to imitate an automated message from company administrative services telling the user they have pending messages due to a server error.

The sender's address is spoofed to look like it came from a company address.
Keep up with the threat feed
Don't miss the next threat feed, and subscribe to our newsletter for the latest feed and cybersecurity content. Stay informed and stay safe!