Email from legitimate app/service (original) (raw)

Summary

Attackers are using legitimate, trusted third-party applications to send phishing lures as part of multi-step attacks requiring user interaction across different sites/mediums.

This approach is effective because:

Examples