The Tracking Parameter That Named the Wrong Company
ID: 2d3c3205-297f-5c68-bc49-b1afb069c56f
STIX ID: report--2d3c3205-297f-5c68-bc49-b1afb069c56f
Feed Name: IRONSCALES
**Executive summary:** A targeted phishing campaign delivered a fabricated Microsoft Teams voicemail notification to director-level mailboxes; the CTA contained a four-layer nested redirect chain that ultimately led to a bystander law-firm domain and included a stale recipient-tracking parameter that reveals kit reuse rather than evidence of a breach. The lure used obfuscation (hidden CSS class, zero-width space, injected hex fragments) and leveraged borrowed infrastructure (SPF-passing bystander domain, no DKIM) to appear legitimate; the message was flagged and quarantined by the security platform, and the report recommends hunting reusable template artifacts (CSS class, injected fragments, nesting order) rather than blocking transient domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
