Analyzing Account Takeover Attacks Leveraging SquarePhish2 and Graphish
Several state-sponsored and financially motivated attacks enabled by SquarePhish2 and Graphish, among other phishing tools, tricked users into granting threat actors access to their Microsoft 365 accounts. The consequences included account takeover, data exfiltration, and others.
Proofpoint identified several IoCs1 associated with the attacks. After a closer look at the original IoC list, we analyzed 46 IoCs in all comprising 21 subdomains (including four with multiple variations), 22 domains, one IP address, and two email addresses.
Using our homegrown tools to investigate the threat, we uncovered these findings:















