Password-Protected PDFs Are the New Sandbox Killer: How a Compromised .gov Account Delivered an Unopenable Payload
ID: 44b5b70f-ff1a-5530-9756-7b36e64271ab
STIX ID: report--44b5b70f-ff1a-5530-9756-7b36e64271ab
Feed Name: IRONSCALES
Attackers compromised a paraprofessional's government Microsoft 365 account and used it to send a password‑protected PDF (passcode plaintext in the email body) to multiple targets via BCC, allowing the message to pass SPF/DKIM/DMARC while preventing automated scanners from opening the attachment; IRONSCALES' community-driven behavioral detection quarantined the messages and the report recommends flagging passcode-plus-attachment patterns, applying behavioral analysis beyond authentication, and hardening trusted .gov/.edu accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
