Google Chrome's Safe Browsing blocklist was used to block a typosquatted Microsoft login domain used in the campaign, prompting the threat actor to switch to KeyVal.
Google Chrome's Safe Browsing blocklist was used to block a typosquatted Microsoft login domain used in the campaign, prompting the threat actor to switch to KeyVal.