Threat Actors Leverage Real Enterprise Email Threads to Deliver Phishing Links
## Cybersecurity: Sophisticated Phishing Tactics in Enterprise Email Threads
Cybersecurity: Sophisticated Phishing Tactics in Enterprise Email Threads
In a recent supply chain phishing attack, threat actors infiltrated an ongoing email thread among C-suite executives regarding a document awaiting approval. The attackers posed as a legitimate participant and inserted a phishing link that mimicked a Microsoft authentication form. This tactic was facilitated by a compromised account of a sales manager at an enterprise contractor, enabling seamless integration into a trusted conversation.
This incident highlights a growing trend where adversaries exploit real enterprise communications instead of crafting generic phishing lures. By early January 2026, analysis linked this incident to a broader campaign active since December 2025, primarily targeting firms in the Middle East.
ANY.RUN Sandbox analysis identified the use of the EvilProxy phishkit, a tool designed to evade traditional session-based detection. Threat intelligence lookups confirmed infrastructure overlaps with known malicious activities.
The attack employed layered social engineering starting with a supply chain attack phishing email sent to the contractor. This initiated a sequence of forwarded messages, enhancing the credibility of the payload as it moved through internal channels.
The final reply included a phishing link leading to:
An antibot landing page protected by Cloudflare Turnstile CAPTCHA. A phishing page with additional Turnstile verification. EvilProxy deployment, capturing credentials via a man-in-the-middle proxy.
This process mimicked legitimate Microsoft 365 flows using dynamic HTML/PDF attachments with embedded scripts. No zero-days or exploits were employed; the success relied on trust and conversation hijacking. The infrastructure parallels phishing-as-a-service platforms in scale, utilizing rented domains and bot mitigation to evade analysts.
The attackers posed as a legitimate participant and inserted a phishing link that mimicked a Microsoft authentication form.
ANY.RUN Sandbox visualized the attack chain, revealing network callbacks to command-and-control servers, credential exfiltration, and session token theft—all occurring within 60 seconds.
Mitigation Strategies and Indicators of Compromise (IOCs)
To counter such threats, organizations should consider the following strategies:
Flag HTML/PDFs with dynamic content and sandbox suspicious files before interaction. Implement the four-eyes principle to separate initiation from approval. Conduct realistic supply chain attack simulations that mimic hijacked threads.
ANY.RUN provides security operation centers with behavioral reports to improve mean time to detect (MTTD) and mean time to respond (MTTR).
Category Indicators
URI Pattern POST ^(/bot/
Domains himsanam[.]com
karaiskou[.]edu[.]gr
Domain Pattern ^loginmicrosoft*
Based on reporting by Cyber Security News.
