On this page:
Attack Spotlight
April 30, 2025
Credential phishing attack with Figma abuse and vendor compromise
Living Off Trusted Service (LOTS) attacks are spreading across SaaS offerings, now leveraging design tools like Figma and Canva. In a recent attack, a bad actor used a linked Figma file to deliver a credential phishing payload. Using design tools like Figma in LOTS attacks is especially effective because they are commonly used in business, are rarely blocked, look like regular work, and bypass link scanning because the payload is multistage.
The attack starts with the target receiving a message from a compromised vendor email account. The target’s email address is BCC’d and the sender’s address is also the main recipient, indicating this has likely been sent to multiple targets at once. The message lets the target know that there is a link to a request for quote (RFQ) on OneDrive within the linked Figma file.
If the target clicks the link, they’re taken to a Figma file with a Click Here To View | Download Documents link that is supposed to take them to the RFQ on OneDrive that’s referenced in the email.
Clicking that link takes the target to a fake Microsoft login screen (hosted at csoaitv[.]org) that harvests credentials.
Sublime's AI-powered detection engine prevented this attack. Some of the top signals for this attack were:
ASA, Sublime’s Autonomous Security Analyst, flagged this email as malicious. Here is ASA’s analysis summary:
LOTS attacks are gaining popularity because they let bad actors hide behind friendly domains. That’s why the most effective email security platforms are adaptive, using AI and machine learning to shine a spotlight on seemingly minor discrepancies.
If you enjoyed this Attack Spotlight, be sure to check our blog every week for new blogs, subscribe to our RSS feed, or sign up for our monthly newsletter. Our newsletter covers the latest blogs, detections, product updates, and more.
Read more Attack Spotlights:
Sublime releases, detections, blogs, events, and more directly to your inbox.
The latest research, attack spotlights, and product updates.
Experience Sublime’s adaptable email security platform and take control of your email environment today.