Phishing Campaign Uses Unique UUIDs to Evade Secure Email Gateways
A new phishing attack identified in early February 2025 successfully circumvents Secure Email Gateways (SEGs) and perimeter defenses using a combination of random domain selection, dynamic UUID generation, and browser session manipulation.
A new phishing attack identified in early February 2025 successfully circumvents Secure Email Gateways (SEGs) and perimeter defenses using a combination of random domain selection, dynamic UUID generation, and browser session manipulation.
This attack employs a specialized JavaScript embedded in malicious attachments and spoofed cloud collaboration platforms, making detection by traditional security tools challenging.
Cofense Intelligence has identified this threat as part of a campaign demonstrating a significant evolution in credential theft tactics, necessitating immediate attention from security professionals globally.
This threat deviates from traditional phishing tactics by utilizing three distinct strategies that require a reevaluation of email security measures.
The attack features a dual UUID method, highlighting its sophistication. The script loads jQuery from a legitimate source, manipulating the page discreetly.
Two identifiers are generated: a hardcoded campaign UUID for tracking the overall campaign and a dynamic session UUID for individual victim monitoring. This dual-tracking mechanism allows threat actors to correlate exfiltrated credentials with specific victims while maintaining campaign-level analytics.
This threat deviates from traditional phishing tactics by utilizing three distinct strategies that require a reevaluation of email security measures.
This approach enables granular victim tracking and suggests a well-resourced threat actor with advanced capabilities. The hardcoded UUID likely serves as a campaign marker, indicating the script's potential reuse across multiple phishing campaigns with different brands.
Instead of traditional multi-domain failover, the script selects a single random .org domain from a predefined list, reducing network traffic and minimizing detection by intrusion detection systems.
The use of .org domains, perceived as legitimate, enhances the attack's ability to bypass reputation-based filtering systems.
The attack dynamically replaces webpage content through server-provided data without altering the browser's URL. After sending an HTTPS POST request with the victim's email and session UUID, the server responds with a crafted login form tailored to the victim's organization.
This technique aligns with the MITRE ATT&CK framework T1185 (Browser Session Hijacking), maintaining victim confidence in the phishing page's legitimacy.
The attack employs HTML-based email attachments and spoofed links impersonating cloud platforms such as Microsoft OneDrive, SharePoint Online, DocuSign, Google Docs, and Adobe Sign.
Organizations must review and enhance their email security controls beyond traditional gateway filtering to counter this evolving threat.
Based on reporting by GBHackers.
