logo

Three Brands, One Lure: A Chase 'Secure Message via Virtru' That Actually Came From LinkedIn

ID: 7caae238-7442-5d3d-9b8b-a5f8ef466710

STIX ID: report--7caae238-7442-5d3d-9b8b-a5f8ef466710

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: [email protected] (Audian Paxson)

...
...

Phishing campaign impersonated JPMorgan Chase using a pixel-accurate "secure message via Virtru" template while the actual From header was [email protected] and CTAs used Mimecast URL-wrapping that resolved toward chase.com; the multi-brand mismatch (brand shown, claimed provider, and sender) and stale canned content exposed credential-harvesting intent. IRONSCALES Themis classified it as phishing (90% confidence), listed IOCs, mapped MITRE techniques (T1566.002, T1656, T1036.005, T1204.001), and recommended identity-consistency checks, link unwrapping, and out-of-band verification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.