logo

Authenticated at Delivery, Forged at Origin

ID: 3a11c1b4-9ef9-55ee-89bd-d08fd09b7df9

STIX ID: report--3a11c1b4-9ef9-55ee-89bd-d08fd09b7df9

Feed Name: IRONSCALES

Threat Score
72/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: [email protected] (Audian Paxson)

...
...

A high-severity spearphishing campaign used an eSignature-themed lure that failed SPF/DMARC at origin but was “laundered” via mailbox auto-forwarding and ARC to appear authenticated at delivery; the CTA routed through a Google open-redirect and ad-click layer to an aged decoy domain (ruslanstudio.com) that harvested credentials. The report includes IOCs (origin IP 188.215.229.105, redirect chain, subject line) and recommends reading full Received chains, treating trusted-domain redirects as suspect, and not relying solely on domain age or final DMARC stamps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.