The Fire Safety Spec That Was Hiding Malware for Five Months
ID: 2cbcdc74-3b19-5877-bcac-a26d22124b8a
STIX ID: report--2cbcdc74-3b19-5877-bcac-a26d22124b8a
Feed Name: IRONSCALES
Attackers planted a malicious PDF (hosted under /wp-content/uploads on a compromised glotest.com WordPress site) inside a legitimate multi-month B2B email thread; the single malicious URL persisted across replies for ~5 months and was eventually flagged by IRONSCALES with 90% AI confidence, triggering quarantine. The report maps the activity to phishing/drive-by compromise techniques and recommends scanning full quoted thread history, retrospective URL rescanning, and heightened suspicion for WordPress-hosted uploads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
