Targeted Phishing Attack Strikes HubSpot Users
Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers. This campaign combines business email compromise tactics with website compromise to distribute credential-stealing malware.
Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers. This campaign combines business email compromise tactics with website compromise to distribute credential-stealing malware.
The attack leverages both compromised infrastructure and spoofed communications. Attackers impersonated HubSpot in emails, urging recipients to verify their accounts due to unusual unsubscribe activity. The phishing URLs were embedded in the sender’s display name, enabling the bypass of email security gateways.
The threat actors used a legitimate email address controlled through business email compromise. This address was employed via MailChimp to distribute the campaign at scale, thus evading secure email gateways due to the trusted reputation of the compromised domain and MailChimp's infrastructure.
Investigation revealed that a legitimate website, canvthis[.]com, was compromised and redirected users to a credential stealer hosted at hxxps://hubspot-campaigns[.]com/login. The fake login page mimics the genuine HubSpot portal. Upon credential entry, information is sent to a server hosted in Saint Petersburg, Russia.
Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers.
The hosting traces back to Proton66 OOO, a Russian bulletproof hosting service. OSINT analysis indicates infrastructure reuse across different campaigns, with the server configured on a Plesk-managed VPS, exposing mail services and using self-issued TLS certificates.
Port scanning shows an extensive attack surface, including DNS, SSH, HTTP/HTTPS, and Plesk interfaces, typical of phishing campaigns using generic VPS templates for rapid deployment.
Threat actors exploit third-party email services like MailChimp and SendGrid, bypassing authentication checks. Security operations teams must enhance detection by monitoring infrastructure patterns and cloud email providers, analyzing TLS artifacts, and implementing user education programs.
This campaign highlights the evolution in phishing sophistication, utilizing brand impersonation and infrastructure-as-a-service to efficiently scale attacks while bypassing basic defenses.
Based on reporting by GBHackers.
