Authenticated at Delivery, Forged at Origin
ID: 3a11c1b4-9ef9-55ee-89bd-d08fd09b7df9
STIX ID: report--3a11c1b4-9ef9-55ee-89bd-d08fd09b7df9
Feed Name: IRONSCALES
A high-severity spearphishing campaign used an eSignature-themed lure that failed SPF/DMARC at origin but was “laundered” via mailbox auto-forwarding and ARC to appear authenticated at delivery; the CTA routed through a Google open-redirect and ad-click layer to an aged decoy domain (ruslanstudio.com) that harvested credentials. The report includes IOCs (origin IP 188.215.229.105, redirect chain, subject line) and recommends reading full Received chains, treating trusted-domain redirects as suspect, and not relying solely on domain age or final DMARC stamps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
