logo

The .pro Domain That Built a Perfect M365 Tenant Just to Send One Google Docs Link

ID: 9218f8a5-2f1b-5032-a07d-f288926a3f34

STIX ID: report--9218f8a5-2f1b-5032-a07d-f288926a3f34

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-10

Date Updated: 2026-05-11

Author: [email protected] (Audian Paxson)

...
...

A phishing campaign used a purpose-built Microsoft 365 tenant on the domain nordicaigrowth.pro that passed SPF/DKIM/DMARC to appear legitimate, delivered a single Google Docs link for likely credential harvesting, and employed social engineering (fabricated In-Reply-To header) plus a geographic routing mismatch between client proxy and mailbox region; behavioral detection (Themis) flagged the message at 84% confidence and quarantined three mailboxes. Indicators provided include the sending domain, sender address, DKIM selector, mailbox server, client proxy, and payload URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.