logo

A DMARC Pass With No SPF, and a CTA Full of Hidden Letters

ID: 3d99afe6-cb16-5664-8d53-66c60c38370f

STIX ID: report--3d99afe6-cb16-5664-8d53-66c60c38370f

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-02

Date Updated: 2026-08-02

Author: [email protected] (Audian Paxson)

...
...

A targeted credential-harvesting phishing message impersonated Fifth Third Bank and bypassed authentication and reputation checks by leveraging a DKIM-aligned signature on an unrelated aged domain while SPF returned None; the attackers hid seven ASCII characters inside near-zero-width inline HTML elements so rendered link text read cleanly but extracted text was garbled. The message redirected users through Outlook Safe Links to a bystander Malaysian domain hosting the landing page, used genuine bank pages as trust cues, and contained multiple IoCs (sending IP 54.240.9.114, Amazon SES message ID, sender/return-path domains, and the decoded CTA path); the report maps the attack to MITRE T1566.002, T1027, and T1204.001 and provides detection and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.