When the Safety Wrapper Becomes the Disguise: Brazilian NF-e Phishing via Safe Links Rewrite
ID: 29a7436b-eaf7-5e54-b114-8bac54b23f4b
STIX ID: report--29a7436b-eaf7-5e54-b114-8bac54b23f4b
Feed Name: IRONSCALES
Attackers used a compromised, authenticated Brazilian sender account to deliver a Portuguese-language NF-e invoice lure that embedded an is.gd shortener; Microsoft Safe Links rewrote the shortener into a safelinks.protection.outlook.com URL, creating a deceptive trust chain that proxied to a two-day-old domain (emissao-br.org) hosting a fake invoice/download prompt. The message was quarantined with SCL 9 after behavioral signals, but the chain demonstrates how authenticated senders + shorteners + time-of-click rewrites can bypass authentication-based filtering; the report includes domain, URL, sending IP, and subject IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
