Open-Source Project Exploited for Large-Scale Phishing Campaign
TL;DR. An open-source project management tool was exploited by a botnet to send over 14,000 phishing invitations. - The attackers created nearly a thousand fake workspaces, each with a phishing subject line. - Invitations were sent from the project's verified domain, directing users to a scam site. - The incident highlights vulnerabilities in hosted open-source platforms and cloud service security.
- A botnet used the cloud version of an open-source project management tool, Kaneo, to launch a phishing attack.
- Over 14,000 phishing invitations were sent from the project's verified email domain, impersonating banks and crypto platforms.
- The attackers demonstrated testing and patience, using unique email providers and timing the attack for early morning UTC.
- The incident underscores risks associated with running cloud services for open-source projects without robust abuse detection.