Purpose-Built Look-Alike Sending Domain Passes Full Authentication to Impersonate Training Brand
ID: 6bb91cb6-7bf2-5143-a743-688b1f4e894b
STIX ID: report--6bb91cb6-7bf2-5143-a743-688b1f4e894b
Feed Name: IRONSCALES
A targeted brand-impersonation phishing campaign sent authenticated webinar invitations using purpose-built look-alike domains (trainingadvantagesending.com and trainingadvantage-mail.com) that mimicked Aurora Training Advantage and matched a known contact's display name; embedded click-tracking URLs routed to a legitimate Eventbrite page to confirm active mailboxes and collect engagement metadata. The attacker-controlled infrastructure passed SPF/DKIM/DMARC with a Microsoft compauth=100 score and used long-lived domains and proper DNS records to evade legacy gateway checks, while behavioral detection (IRONSCALES) quarantined the messages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
