logo

SPF Pass, DKIM Pass, DMARC Pass. Still Phishing.

ID: 7a6a44b4-924f-523e-aa4a-3f210f41b9c8

STIX ID: report--7a6a44b4-924f-523e-aa4a-3f210f41b9c8

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: [email protected] (Audian Paxson)

...
...

An attacker registered a cousin domain of a legitimate Mexican supplier, configured SPF/DKIM/DMARC, and sent a well-crafted Spanish ERP invoice PDF to multiple procurement staff; the PDF and links were clean but a behavioral sender-fingerprint mismatch (display name vs historical sender address) flagged impersonation and quarantined the messages. IOCs provided include the malicious sender address, originating IP, PDF MD5, and an anomalous X-Mailer string.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.