Triple-Brand Credential Harvest: How Attackers Fuse Microsoft, Oracle, and NetSuite to Phish Financial Services
ID: 0d7d28b6-5134-5bf5-9e53-211e508eaa64
STIX ID: report--0d7d28b6-5134-5bf5-9e53-211e508eaa64
Feed Name: IRONSCALES
Attackers registered a freshly created .cz domain and used Amazon SES to send a credential-harvesting spearphish to a Chief Mortgage Officer at a mid-market financial institution; the message combined Microsoft, Oracle, and NetSuite branding, passed SPF/DKIM, bypassed the Secure Email Gateway, and redirected recipients to a compromised third-party URL. IRONSCALES Themis detected and quarantined the message at 85% confidence; the report provides IoCs, MITRE ATT&CK mappings, detection signals, and defender recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
