I don't normally post tweets but Microsoft don't normally use the word "rampant".
https://twitter.com/MsftSecIntel/sta...62191304019968We’re tracking a rampant phishing attack that uses DGA domains, free email services, and even compromised email accounts to send massive numbers of phishing emails. These emails are linked by open redirector URLs that begin with a distinct pattern: hxxps://t[.]domain[.]tld/r/?