New CalPhishing Campaign Uses Internal Email Forwards to Reach Targets

Fortra Intelligence and Research Experts (FIRE) have identified a new CalPhishing variant where attackers exploit internal referrals to conduct credential theft attacks. 

Key takeaways:

  • Attackers pose as prospective customers and contact non-sales employees first.
  • Employees unknowingly become “trust bridges” by forwarding meeting-booking links to sales teams.
  • The booking page appears legitimate but ultimately prompts users to sign in with Microsoft 365 credentials.
  • The attack abuses trusted business workflows instead of spoofed identities or compromised accounts.
  • A successful compromise can lead to email access, data theft, fraud, and further phishing attacks.

Full analysis here: https://www.fortra.com/blog/calphishing-through-trust-chain

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading