Evernote Fake Payment Receipt Credential Phishing Attack
Initial Email Content
Check#6253
Dear, Team
View attached Statements
Best regards,
[Impersonated Name]
[Impersonated Title]
[Impersonated Company Name]
[Impersonated Phone Numbers]
The information contained in this transmission may contain privileged and confidential information, including patient information protected by federal and state privacy laws. It is intended only for the use of the person(s) named above. If you are not the intended recipient, you are hereby notified that any review, dissemination, distribution, or duplication of this communication is strictly prohibited. If you are not the intended recipient, please contact the sender by reply email and destroy all copies of the original message.
Malicious Artifacts
Additional Indicators of Compromise
Type
Description
Attack Description
This link-based attack impersonates Evernote and an external third party using a fake attachment, compromised external account, and a fake payment receipt theme to steal credentials.