logo

A Generic Extortion Template, a Mailgun Relay, and a Domain Registered to Look Legitimate

ID: 3b85a06d-5031-5cd4-8997-ad0690d3a122

STIX ID: report--3b85a06d-5031-5cd4-8997-ad0690d3a122

Feed Name: IRONSCALES

Threat Score
50/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: [email protected] (Audian Paxson)

...
...

**Executive Summary:** A Mailgun-relayed sextortion campaign used a newly registered domain (athletes2events.com) with DKIM alignment to circumvent SPF failures and delivered a generic $12,000 Bitcoin extortion demand to a VIP mailbox; IRONSCALES' Adaptive AI quarantined the message and the report documents authentication outcomes, behavioral detection logic, IOCs, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.