publishing date icon
September 8, 2023
read time icon
5 min. read

Threat feed week 36: Disney+, Xerox, SharePoint impersonations and a fake voicemail notification

Author image
Threat Analyst Team
Post hero image

Table of contents

share this post

Disney+ impersonation

Hox rating: ★★✩✩

Threat type: Bulk phishing

Payload: Malicious phone number

Region: Global

Analyst: Minna Herlevi

Date: 08.09.2023

This phishing email is impersonating Disney+.

It attempts to create a scenario where the recipient forgot to cancel their subscription and has to call the included number to cancel it. The subscription cost has been increased by 500% to increase urgency.

Xerox fax impersonation

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 08.09.2023

This phishing email is a fake Xerox fax notification.

The recipient needs to click the link to download the fax, but the link leads to an unrelated site hosting the payload.

SharePoint impersonation

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 08.09.2023

This phishing email is impersonating SharePoint.

The email originates from an unrelated address, and the payload link uses an open redirect through Baidu to mask the real destination.

Voicemail notification

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious attachment

Region: Global

Analyst: Minna Herlevi

Date: 08.09.2023

This phishing email is pretending to be a voicemail notification. Attackers are using curiosity to get the recipient to open the attachment— besides, the voicemail could be relevant or important.

In reality, the attachment is an HTML file instead of an audio file such as .wav or .mp3.

Keep up with the threat feed

Don't miss the next threat feed, and subscribe to our newsletter for the latest feed and cybersecurity content. Stay informed and stay safe!

Subscribe to All Things Human Risk

Subscribe to our newsletter for a curated digest of the latest news, articles, and resources on human risk and evolving phishing threats in the ever-changing landscape.

Hoxhunt needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at anytime. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, check out our Privacy Policy.