Three Brands, One Lure: A Chase 'Secure Message via Virtru' That Actually Came From LinkedIn
ID: 7caae238-7442-5d3d-9b8b-a5f8ef466710
STIX ID: report--7caae238-7442-5d3d-9b8b-a5f8ef466710
Feed Name: IRONSCALES
Phishing campaign impersonated JPMorgan Chase using a pixel-accurate "secure message via Virtru" template while the actual From header was [email protected] and CTAs used Mimecast URL-wrapping that resolved toward chase.com; the multi-brand mismatch (brand shown, claimed provider, and sender) and stale canned content exposed credential-harvesting intent. IRONSCALES Themis classified it as phishing (90% confidence), listed IOCs, mapped MITRE techniques (T1566.002, T1656, T1036.005, T1204.001), and recommended identity-consistency checks, link unwrapping, and out-of-band verification.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
