Telephone-Oriented Attack Delivery (TOAD) is a threat campaign pattern that uses multi-channel social engineering, often incorporating voice-based outreach and credible-looking enterprise signals to deliver credentials or access tokens.
Telephone-Oriented Attack Delivery (TOAD) is a threat campaign pattern that uses multi-channel social engineering, often incorporating voice-based outreach and credible-looking enterprise signals to deliver credentials or access tokens. Recent campaigns exploit legitimate workflows and brand assets to improve plausibility, making credential theft and account compromise more likely. Its significance lies in combining trusted identity mechanisms with persuasive social engineering to bypass user skepticism and security controls.
A new phishing campaign, identified as TOAD, has been targeting Microsoft Entra guest invitees by sending fake invoices. The campaign was uncovered by threat researcher Matt Taggart and associates over the weekend,…
A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to…