logo

Triple-Brand Credential Harvest: How Attackers Fuse Microsoft, Oracle, and NetSuite to Phish Financial Services

ID: 0d7d28b6-5134-5bf5-9e53-211e508eaa64

STIX ID: report--0d7d28b6-5134-5bf5-9e53-211e508eaa64

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-03-28

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers registered a freshly created .cz domain and used Amazon SES to send a credential-harvesting spearphish to a Chief Mortgage Officer at a mid-market financial institution; the message combined Microsoft, Oracle, and NetSuite branding, passed SPF/DKIM, bypassed the Secure Email Gateway, and redirected recipients to a compromised third-party URL. IRONSCALES Themis detected and quarantined the message at 85% confidence; the report provides IoCs, MITRE ATT&CK mappings, detection signals, and defender recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.