Skip to content

Phishing

  • ![[Attachments/Pasted image 20260305151329.png]]

Scenario

  • Rohit Agarwal recently shared on LinkedIn that he has joined a Managed Security Services Provider (MSSP), which lists Gigantic Retail as a client on its website. As part of our red team engagement for Gigantic Retail, we are targeting this user to gain an initial foothold into their environment via the MSSP.

Objective

  • Use the phishing page (https://aka-accountreview.cloud/) to capture the target user’s credentials. Once obtained, extract the username and password from creds.txt, and attempt to access any sensitive information available through the compromised account.

  • ![[Attachments/Pasted image 20260305165009.png]]
  • ![[Attachments/Pasted image 20260305165100.png]]