Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Phishing Campaign Uses Unique UUIDs to Evade Secure Email Gateways

A new phishing attack identified in early February 2025 successfully circumvents Secure Email Gateways (SEGs) and perimeter defenses using a combination of random domain selection, dynamic UUID generation, and browser session manipulation.

A new phishing attack identified in early February 2025 successfully circumvents Secure Email Gateways (SEGs) and perimeter defenses using a combination of random domain selection, dynamic UUID generation, and browser session manipulation.

This attack employs a specialized JavaScript embedded in malicious attachments and spoofed cloud collaboration platforms, making detection by traditional security tools challenging.

Cofense Intelligence has identified this threat as part of a campaign demonstrating a significant evolution in credential theft tactics, necessitating immediate attention from security professionals globally.

This threat deviates from traditional phishing tactics by utilizing three distinct strategies that require a reevaluation of email security measures.

The attack features a dual UUID method, highlighting its sophistication. The script loads jQuery from a legitimate source, manipulating the page discreetly.

Two identifiers are generated: a hardcoded campaign UUID for tracking the overall campaign and a dynamic session UUID for individual victim monitoring. This dual-tracking mechanism allows threat actors to correlate exfiltrated credentials with specific victims while maintaining campaign-level analytics.

This threat deviates from traditional phishing tactics by utilizing three distinct strategies that require a reevaluation of email security measures.
Olivia Harper · Thehackingpost

This approach enables granular victim tracking and suggests a well-resourced threat actor with advanced capabilities. The hardcoded UUID likely serves as a campaign marker, indicating the script's potential reuse across multiple phishing campaigns with different brands.

Instead of traditional multi-domain failover, the script selects a single random .org domain from a predefined list, reducing network traffic and minimizing detection by intrusion detection systems.

The use of .org domains, perceived as legitimate, enhances the attack's ability to bypass reputation-based filtering systems.

The attack dynamically replaces webpage content through server-provided data without altering the browser's URL. After sending an HTTPS POST request with the victim's email and session UUID, the server responds with a crafted login form tailored to the victim's organization.

Advertisement

This technique aligns with the MITRE ATT&CK framework T1185 (Browser Session Hijacking), maintaining victim confidence in the phishing page's legitimacy.

The attack employs HTML-based email attachments and spoofed links impersonating cloud platforms such as Microsoft OneDrive, SharePoint Online, DocuSign, Google Docs, and Adobe Sign.

Organizations must review and enhance their email security controls beyond traditional gateway filtering to counter this evolving threat.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories