logo

Three Security Wrappers, One Redirect to a Google Docs Phishing Page

ID: 2f123f1f-3ec6-5121-ac2d-9d7d2592d3e7

STIX ID: report--2f123f1f-3ec6-5121-ac2d-9d7d2592d3e7

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-20

Date Updated: 2026-06-20

Author: [email protected] (Audian Paxson)

...
...

A high-severity credential-harvesting phishing campaign impersonated an internal document share, routing a single CTA through Oracle EdgePilot and Barracuda LinkProtect to an attacker-controlled domain and finally to a Google Slides payload; the message failed SPF/DKIM/DMARC but was still delivered to the inbox due to intermediary relay behavior, and IRONSCALES' Themis flagged it at 84% confidence. The report includes MITRE mappings and IoCs (sender, redirect domain, wrappers, sending IPs) and highlights how link-protection services were abused as camouflage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.