Redteam phishing payloads in 2023?

Just curious what people are using as payloads for phishing these days. Since Microsoft disabled downloaded files with macros, that no longer seems like a viable option.

HTA files seems to be unreliable and Jscript files no long get executed by default on Win11.

The only other things are LNK’s, but even then that requires users to run it past smart screen. I suspect even in a .zip Office365 etc would block the download.

Malware seems to be sticking to LNK and HTA. Or even some encouring enabling macro post download.

Curious what any of you guys have used in Q3 2023.

submitted by /u/thehunter699
[link] [comments]

November 1, 2023
Read More >>

Furl – Wayback Machine URL Mining For Bug Hunting

Furl is a tool for mining URLs from Wayback Machine for bug hunting/fuzzing/further probing. Furl is a powerful tool designed for bug hunters, fuzzers, and those seeking to probe the depths of the web. This article explores how Furl can be used to mine URLs from the Wayback Machine, opening up new possibilities for uncovering […]

November 1, 2023
Read More >>