logo

Seeing both sides of a service abuse financial fraud using YOPmail disposable messages · Blog · Sublime Security

ID: b0e8f3da-684c-579e-bda5-4ff782ba0fe2

STIX ID: report--b0e8f3da-684c-579e-bda5-4ff782ba0fe2

Feed Name: Sublime Security Blog

Threat Score
50/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

This report outlines a callback phishing campaign that abused Adobe signing requests and distribution-list relays to deliver fraudulent invoice emails; attackers used a YOPmail reply-to (a disposable, publicly viewable inbox) to receive victim replies and scale multiple campaigns. The writeup includes attack anatomy, observed responder data from YOPmail, evidence the attacker operated multiple relays, and detection signals (e.g., new distribution list usage, suspicious document notification language, cryptocurrency mentions) used by Sublime to prevent the attack.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.