logo

Hackers Abuse Apple & PayPal Invoice Emails in DKIM Replay Attack Campaign

ID: 9e101c56-57ef-5d63-8b28-2a85d3eddfa5

STIX ID: report--9e101c56-57ef-5d63-8b28-2a85d3eddfa5

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

The report documents DKIM replay attacks in which attackers abuse user-supplied fields on trusted services (Apple, PayPal, DocuSign, HelloSign) to embed scam instructions into legitimately signed emails; those emails are then forwarded to victims and pass DKIM/DMARC checks, enabling convincing phishing, payment fraud, and remote-access malware installation. INKY researchers observed real campaigns and recommend inspecting headers for forwarding, being wary of phone numbers in messages, educating users, and validating notifications via official sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.