The Attachment Inside the Attachment: How Nested RFC822 Messages Evade Parser-Based Detection
ID: 0eb07cb7-b408-518d-96b1-a28a2e966feb
STIX ID: report--0eb07cb7-b408-518d-96b1-a28a2e966feb
Feed Name: IRONSCALES
Threat Score
A targeted phishing email delivered a nested message/rfc822 attachment (76,583 bytes) with CR/LF characters injected into the filename to exploit parser inconsistencies across email security tools; a second delivery-status attachment was unretrievable for inspection, the sending domain published DMARC with p=none, and IRONSCALES' behavioral detection quarantined the message before the nested payload could be opened.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
