logo

When the Phishing Kit Ships Early: Exposed Template Variables Reveal Attack Infrastructure

ID: 0304ef83-ca48-570a-9d22-eee783e53b16

STIX ID: report--0304ef83-ca48-570a-9d22-eee783e53b16

Feed Name: IRONSCALES

Threat Score
50/100

Date Published: 2026-04-25

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A credential‑harvesting phishing email sent from a compromised authenticated account bypassed spoofing checks (SPF/DKIM/DMARC) and contained unresolved template tokens and a placeholder URL (http://vm/), indicating a phishing kit was deployed before configuration; behavioral detection flagged and quarantined the message and the exposed artifacts provide actionable IOCs and TTPs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.