Simple Mail Transfer Pirates: How threat actors are abusing third-party infrastructure to send spam
ID: a21eb217-7fa2-55cf-9a02-1272c039a2d0
STIX ID: report--a21eb217-7fa2-55cf-9a02-1272c039a2d0
Feed Name: Cisco Talos
Cisco Talos details how spammers abuse legitimate web forms (e.g., account registration, events, contact forms) and Google apps (Drawings, Sheets, Forms, Calendar, Groups) to send spam from trusted infrastructure, while also credential-stuffing IMAP/SMTP to hijack outbound email. The report highlights tools like MadCat and MailRip, a marketplace selling working SMTP credentials, and common test email subject lines that can serve as detection leads, and recommends mitigations including unique passwords, password managers, and user education.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
