The .pro Domain That Built a Perfect M365 Tenant Just to Send One Google Docs Link
ID: 9218f8a5-2f1b-5032-a07d-f288926a3f34
STIX ID: report--9218f8a5-2f1b-5032-a07d-f288926a3f34
Feed Name: IRONSCALES
A phishing campaign used a purpose-built Microsoft 365 tenant on the domain nordicaigrowth.pro that passed SPF/DKIM/DMARC to appear legitimate, delivered a single Google Docs link for likely credential harvesting, and employed social engineering (fabricated In-Reply-To header) plus a geographic routing mismatch between client proxy and mailbox region; behavioral detection (Themis) flagged the message at 84% confidence and quarantined three mailboxes. Indicators provided include the sending domain, sender address, DKIM selector, mailbox server, client proxy, and payload URL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
