logo

The Contract Email That Wasn't Spelled the Way You Think: Unicode Homoglyphs, a QR Code, and a Marketing Gateway

ID: 1dde2759-a0b9-5a09-892f-2ad5cbee3d71

STIX ID: report--1dde2759-a0b9-5a09-892f-2ad5cbee3d71

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: [email protected] (Audian Paxson)

...
...

**Executive Summary:** A high-severity phishing campaign used Unicode homoglyphs and zero-width joiners in the sender local-part to impersonate '[email protected]', passed SPF/DKIM/DMARC via Brevo's marketing relay, contained no inline links but a QR code to conceal the phishing destination, and included a 1x1 tracking pixel to confirm active mailboxes; behavioral signals (first-time sender, subject/body mismatch, QR-only CTA) led Themis to quarantine the message.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.