Seeing both sides of a service abuse financial fraud using YOPmail disposable messages · Blog · Sublime Security
ID: b0e8f3da-684c-579e-bda5-4ff782ba0fe2
STIX ID: report--b0e8f3da-684c-579e-bda5-4ff782ba0fe2
Feed Name: Sublime Security Blog
This report outlines a callback phishing campaign that abused Adobe signing requests and distribution-list relays to deliver fraudulent invoice emails; attackers used a YOPmail reply-to (a disposable, publicly viewable inbox) to receive victim replies and scale multiple campaigns. The writeup includes attack anatomy, observed responder data from YOPmail, evidence the attacker operated multiple relays, and detection signals (e.g., new distribution list usage, suspicious document notification language, cryptocurrency mentions) used by Sublime to prevent the attack.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
