logo

Interactive Brokers W-8BEN Lure Hid Behind a 0-Day Domain

ID: 42dff869-f294-5cf3-b847-6eb78c8b8139

STIX ID: report--42dff869-f294-5cf3-b847-6eb78c8b8139

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: [email protected] (Audian Paxson)

...
...

A phishing campaign impersonating Interactive Brokers sent W-8BEN renewal emails that linked to a zero-day domain (ehdgmsrd.com) registered the same day and hidden behind a Cloudflare challenge; the recipient organization's link-protection proxy loaded its proxy page and reported the URL clean while the underlying credential-harvest page remained unreachable to scanners, enabling credential theft. Indicators include sending domain jlrimes.com (DKIM body-hash fail, DMARC p=none), sender [email protected], and the EdgePilot-wrapped CTA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.