logo

Funding Agreement, Forged Approval: How a Three-Layer Redirect Chain Targeted Finance Leadership

ID: 0d633d83-0005-5427-9b83-6d3150b2d3f9

STIX ID: report--0d633d83-0005-5427-9b83-6d3150b2d3f9

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-24

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted spearphishing campaign impersonated a funding-agreement document notification to a VP of Finance, delivered via Amazon SES and concealed behind a three-hop redirect chain (Cisco Secure Web → compromised Argentinian redirector → haystack.so credential page). Authentication checks showed SPF passing for the SES relay but DKIM and DMARC failing for the claimed sender; IRONSCALES Adaptive AI quarantined the message seconds after delivery. Key IOCs include elettro-coltura.com, 54.240.3.30, waterpowerinn.com.ar, and 4creeks.haystack.so; recommended actions are enforce DMARC reject/quarantine, treat display/href mismatches as high-confidence, audit SES configurations, and add behavioral AI detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.