Funding Agreement, Forged Approval: How a Three-Layer Redirect Chain Targeted Finance Leadership
ID: 0d633d83-0005-5427-9b83-6d3150b2d3f9
STIX ID: report--0d633d83-0005-5427-9b83-6d3150b2d3f9
Feed Name: IRONSCALES
A targeted spearphishing campaign impersonated a funding-agreement document notification to a VP of Finance, delivered via Amazon SES and concealed behind a three-hop redirect chain (Cisco Secure Web → compromised Argentinian redirector → haystack.so credential page). Authentication checks showed SPF passing for the SES relay but DKIM and DMARC failing for the claimed sender; IRONSCALES Adaptive AI quarantined the message seconds after delivery. Key IOCs include elettro-coltura.com, 54.240.3.30, waterpowerinn.com.ar, and 4creeks.haystack.so; recommended actions are enforce DMARC reject/quarantine, treat display/href mismatches as high-confidence, audit SES configurations, and add behavioral AI detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
