logo

An Encrypted Attachment, an Empty Body, and a Scanner That Couldn't Look Inside

ID: 88caab35-36f7-5f9f-985c-92be38ee200a

STIX ID: report--88caab35-36f7-5f9f-985c-92be38ee200a

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A compromised Microsoft 365 account was used to send a blank-bodied email with a 540KB encrypted RPMSG attachment and High Importance flags to a forensic engineering firm; because the RPMSG was encrypted, automated scanners returned a misleading "clean" verdict while authentication checks (SPF/DKIM/DMARC/ARC) passed, creating a functional blind spot that enabled credential-harvesting/social-engineering. Themis flagged the message based on structural anomalies, and the report recommends treating encrypted attachments from external senders as elevated risk and shifting detection to behavioral analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.