The Subdomain That Fused Two Trusted Brands Into One Convincing Lie
ID: 15c0bbc6-ea18-555e-8438-5bfdcdc8d6b3
STIX ID: report--15c0bbc6-ea18-555e-8438-5bfdcdc8d6b3
Feed Name: IRONSCALES
Threat Score
Attackers provisioned a subdomain under Zix's secureemailportal.com (fidelityusa.secureemailportal.com) to send authenticated-looking spearphishing messages to a community bank's business banking inbox, leveraging Zix's DKIM/SPF/DMARC reputation while directing replies to an attacker-controlled domain (fidelity-usa.com); behavioral detection of sender/Reply-To divergence flagged and quarantined the messages before credential harvesting succeeded.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
