logo

When the Sender Domain Is Also the Phishing Kit Host: Dual-Purpose Domain Compromise

ID: 8018ae59-3cdf-5179-9733-cb55f898db68

STIX ID: report--8018ae59-3cdf-5179-9733-cb55f898db68

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-27

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers compromised a long-established manufacturing domain and weaponized it twice: as an authenticated Amazon SES sender and as the hosting domain for a DocSend-themed credential harvest page. The targeted spear-phish used a time-sensitive HR open-enrollment lure, passed SPF/DKIM/DMARC (making authentication unreliable as a trust signal), and included tokenized links and AWS click-tracking; the email was quarantined before any credentials were captured, but IOCs and mitigation guidance are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.