logo

When Your Security Vendor's OAuth Endpoint Is the Phishing Link

ID: 5766a926-d768-54b7-b7a5-96b6d0aa245f

STIX ID: report--5766a926-d768-54b7-b7a5-96b6d0aa245f

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted credential-harvesting phishing campaign impersonated Pandora and embedded a CTA pointing to Mimecast's legitimate OAuth2 authorization endpoint with a redirect_uri that landed on an attacker-controlled callback; because the link resolved to api.services.mimecast.com and authentication (SPF/DMARC) passed, reputation-based scanners rated it clean. The report outlines the delivery chain (Amazon SES → Mimecast relay → Exchange Online), explains how Mimecast's body rewriting caused DKIM body-hash failures that masked risk signals, and recommends behavioral detection (e.g., flagging OAuth authorize URLs in transactional emails and parsing redirect_uri parameters) alongside specific IOCs (sending domain calclean.com, sender [email protected], IP 54.240.9.30, and the OAuth/redirect URLs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.