Security advisories

Credential Harvesting Campaign Targeting Entertainment Industry

July 25, 2019 | 1 MIN READ

Speak With A Security Expert Now

TALK TO AN EXPERT

The Threat

Threat Connect researchers have published information on an ongoing credential harvesting campaign targeting companies in the entertainment industry. The campaign has been active since 2017, with the most recently identified indicators were found in mid-July 2019. This campaign consists of threat actor(s) registering domains that impersonate legitimate entertainment websites; the domains’ host credential phishing pages. The threat actor’(s) long term goals are not known at this time.

All known indicators from this campaign have been checked against the eSentire client base; no positive results were identified.

What we’re doing about it

What you should do about it

Additional information

The delivery method used by threat actors in this campaign has not been observed. It is highly likely that the threat actors are employing phishing emails to trick end users into visiting the malicious domains.

For more information on this ongoing campaign see the original research by Threat Connect. Note, that indicators in this paper are not up to date.

View Most Recent Advisories