logo

RE: Christopher: How a Thread Hijack Rode Salesforce Marketing Cloud Into the Inbox

ID: 3f6e9a83-e5fd-5167-993c-9ec80190bb7c

STIX ID: report--3f6e9a83-e5fd-5167-993c-9ec80190bb7c

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-27

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Executive Summary:** This report details a high-severity phishing thread‑hijack that abused Salesforce Marketing Cloud and Pardot infrastructure to send a convincing "RE:Christopher" reply from the domain stackpilotit.com (registered 2025-06-13), passing SPF/DKIM/DMARC and using platform bounce/unsubscribe links to appear legitimate; Microsoft marked it SCL 5 while Themis quarantined it before user interaction. The write-up includes MITRE ATT&CK mappings and discrete IOCs for defenders to block or monitor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.