logo

When the Safety Wrapper Becomes the Disguise: Brazilian NF-e Phishing via Safe Links Rewrite

ID: 29a7436b-eaf7-5e54-b114-8bac54b23f4b

STIX ID: report--29a7436b-eaf7-5e54-b114-8bac54b23f4b

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers used a compromised, authenticated Brazilian sender account to deliver a Portuguese-language NF-e invoice lure that embedded an is.gd shortener; Microsoft Safe Links rewrote the shortener into a safelinks.protection.outlook.com URL, creating a deceptive trust chain that proxied to a two-day-old domain (emissao-br.org) hosting a fake invoice/download prompt. The message was quarantined with SCL 9 after behavioral signals, but the chain demonstrates how authenticated senders + shorteners + time-of-click rewrites can bypass authentication-based filtering; the report includes domain, URL, sending IP, and subject IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.