Home / Companies / Sublime Security / Blog / Post Details
Content Deep Dive

Detecting malicious AnonymousFox email messages sent from compromised sites

Blog post from Sublime Security

Post Details
Date Published
Author
Sam Scholten
Word Count
571
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

AnonymousFox is a threat actor group active since 2019, targeting vulnerabilities in CMS platforms like WordPress, Drupal, Joomla, and OpenCart through tools such as FoxAuto and Fox-CGI, which grant full control over compromised websites for malicious activities including password resets, script uploads, and phishing attacks. Despite available prevention resources, these attacks persist, with recent spikes in activity, leading to compromised sites sending out phishing emails that bypass spam filters. Sublime's AI-powered detection engine effectively identifies and mitigates these threats by analyzing email headers for specific artifacts like "anonymousfox" or "smtpfox," ensuring such malicious messages are kept out of mailboxes. The software uses a combination of open-source detection rules and advanced AI techniques to combat evolving threats, offering users tools to protect their email systems from these persistent attacks.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.