When the Sender Domain Is Also the Phishing Kit Host: Dual-Purpose Domain Compromise
ID: 8018ae59-3cdf-5179-9733-cb55f898db68
STIX ID: report--8018ae59-3cdf-5179-9733-cb55f898db68
Feed Name: IRONSCALES
Attackers compromised a long-established manufacturing domain and weaponized it twice: as an authenticated Amazon SES sender and as the hosting domain for a DocSend-themed credential harvest page. The targeted spear-phish used a time-sensitive HR open-enrollment lure, passed SPF/DKIM/DMARC (making authentication unreliable as a trust signal), and included tokenized links and AWS click-tracking; the email was quarantined before any credentials were captured, but IOCs and mitigation guidance are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
