logo

Simple Mail Transfer Pirates: How threat actors are abusing third-party infrastructure to send spam

ID: a21eb217-7fa2-55cf-9a02-1272c039a2d0

STIX ID: report--a21eb217-7fa2-55cf-9a02-1272c039a2d0

Feed Name: Cisco Talos

Date Published: 2024-09-26

Date Updated: 2026-04-27

Author: Jaeson Schultz

...
...

Cisco Talos details how spammers abuse legitimate web forms (e.g., account registration, events, contact forms) and Google apps (Drawings, Sheets, Forms, Calendar, Groups) to send spam from trusted infrastructure, while also credential-stuffing IMAP/SMTP to hijack outbound email. The report highlights tools like MadCat and MailRip, a marketplace selling working SMTP credentials, and common test email subject lines that can serve as detection leads, and recommends mitigations including unique passwords, password managers, and user education.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.