Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Targeted Phishing Attack Strikes HubSpot Users

Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers. This campaign combines business email compromise tactics with website compromise to distribute credential-stealing malware.

Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers. This campaign combines business email compromise tactics with website compromise to distribute credential-stealing malware.

The attack leverages both compromised infrastructure and spoofed communications. Attackers impersonated HubSpot in emails, urging recipients to verify their accounts due to unusual unsubscribe activity. The phishing URLs were embedded in the sender’s display name, enabling the bypass of email security gateways.

The threat actors used a legitimate email address controlled through business email compromise. This address was employed via MailChimp to distribute the campaign at scale, thus evading secure email gateways due to the trusted reputation of the compromised domain and MailChimp's infrastructure.

Investigation revealed that a legitimate website, canvthis[.]com, was compromised and redirected users to a credential stealer hosted at hxxps://hubspot-campaigns[.]com/login. The fake login page mimics the genuine HubSpot portal. Upon credential entry, information is sent to a server hosted in Saint Petersburg, Russia.

Evalian's Security Operations Centre has identified an ongoing sophisticated phishing campaign targeting HubSpot customers.
Thomas Blake · Thehackingpost

The hosting traces back to Proton66 OOO, a Russian bulletproof hosting service. OSINT analysis indicates infrastructure reuse across different campaigns, with the server configured on a Plesk-managed VPS, exposing mail services and using self-issued TLS certificates.

Port scanning shows an extensive attack surface, including DNS, SSH, HTTP/HTTPS, and Plesk interfaces, typical of phishing campaigns using generic VPS templates for rapid deployment.

Threat actors exploit third-party email services like MailChimp and SendGrid, bypassing authentication checks. Security operations teams must enhance detection by monitoring infrastructure patterns and cloud email providers, analyzing TLS artifacts, and implementing user education programs.

Advertisement

This campaign highlights the evolution in phishing sophistication, utilizing brand impersonation and infrastructure-as-a-service to efficiently scale attacks while bypassing basic defenses.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories