The SharePoint Share That Passed Every Check: A Compromised M365 Tenant With DMARC Reject and Tokenized Links
ID: 930daa45-4110-5d42-89b6-0559ae2872be
STIX ID: report--930daa45-4110-5d42-89b6-0559ae2872be
Feed Name: IRONSCALES
Threat Score
A compromised Microsoft 365 tenant (packnfresh.com) was used to send authentic-looking SharePoint sharing notifications that passed SPF/DKIM/DMARC and resolved to legitimate Microsoft-hosted SharePoint links containing tokenized parameters; formatting anomalies and behavioral signals revealed the credential-harvesting phishing attempt, leading to quarantine of the mailbox and publication of IoCs and ATT&CK mappings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
