logo

The Fire Safety Spec That Was Hiding Malware for Five Months

ID: 2cbcdc74-3b19-5877-bcac-a26d22124b8a

STIX ID: report--2cbcdc74-3b19-5877-bcac-a26d22124b8a

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: [email protected] (Audian Paxson)

...
...

Attackers planted a malicious PDF (hosted under /wp-content/uploads on a compromised glotest.com WordPress site) inside a legitimate multi-month B2B email thread; the single malicious URL persisted across replies for ~5 months and was eventually flagged by IRONSCALES with 90% AI confidence, triggering quarantine. The report maps the activity to phishing/drive-by compromise techniques and recommends scanning full quoted thread history, retrospective URL rescanning, and heightened suspicion for WordPress-hosted uploads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.