logo

Purpose-Built Look-Alike Sending Domain Passes Full Authentication to Impersonate Training Brand

ID: 6bb91cb6-7bf2-5143-a743-688b1f4e894b

STIX ID: report--6bb91cb6-7bf2-5143-a743-688b1f4e894b

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-11

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted brand-impersonation phishing campaign sent authenticated webinar invitations using purpose-built look-alike domains (trainingadvantagesending.com and trainingadvantage-mail.com) that mimicked Aurora Training Advantage and matched a known contact's display name; embedded click-tracking URLs routed to a legitimate Eventbrite page to confirm active mailboxes and collect engagement metadata. The attacker-controlled infrastructure passed SPF/DKIM/DMARC with a Microsoft compauth=100 score and used long-lived domains and proper DNS records to evade legacy gateway checks, while behavioral detection (IRONSCALES) quarantined the messages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.