logo

The Attachment Inside the Attachment: How Nested RFC822 Messages Evade Parser-Based Detection

ID: 0eb07cb7-b408-518d-96b1-a28a2e966feb

STIX ID: report--0eb07cb7-b408-518d-96b1-a28a2e966feb

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted phishing email delivered a nested message/rfc822 attachment (76,583 bytes) with CR/LF characters injected into the filename to exploit parser inconsistencies across email security tools; a second delivery-status attachment was unretrievable for inspection, the sending domain published DMARC with p=none, and IRONSCALES' behavioral detection quarantined the message before the nested payload could be opened.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.