Bellingcat @bellingcat Award-winning open source investigation. Want to donate? See here: www.patreon.com/bellingcat Aug. 10, 2019 1 min read

Major update on the ProtonMail phishing attacks, establishing over 30 individuals working on topics related to Russia have been targeted.  https://www.bellingcat.com/news/uk-and-europe/2019/08/10/guccifer-rising-months-long-phishing-campaign-on-protonmail-targets-dozens-of-russia-focused-journalists-and-ngos/ 

The target list includes journalists and investigators working for @guardian, @BBCNews, @_EuropeanValues, @4freerussia_org, and others.

There's a lot of interesting things to be found in the Javascript used as part of the attack, including a phrase used by Guccifer 2.0.

Bellingcat managed to grab a copy of the fake ProtonMail site used in the phishing attacks, and is making the core Javascript files used by the phishing site available for analysis. You can download the files here  https://bitbucket.org/bellingcat/fakeproton/downloads/ 


You can follow @bellingcat.



Bookmark

____
Tip: mention @threader_app on a Twitter thread with the keyword “compile” to get a link to it.

Enjoy Threader? Sign up.