logo

A Valid DKIM Signature Over an Unauthorized Message

ID: a98534d5-8c32-5859-b4eb-8dea532c9481

STIX ID: report--a98534d5-8c32-5859-b4eb-8dea532c9481

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: [email protected] (Audian Paxson)

...
...

A senior executive received a spearphishing email that passed SPF/DKIM/DMARC because an unauthenticated submission was accepted and relayed by a legitimate Microsoft 365 tenant, which applied a valid DKIM signature and outbound SPF. The message carried a nested .eml attachment containing a QR code that decoded to a pre-filled credential-harvesting landing page; detection relied on behavioral signals and a human analyst. Indicators provided include the originating IP (96.9.214.101), HELO string (speedy-negotiation), malicious domain (gambiit.net), URL from the QR code, the attachment name (Earnings_Adjustment.eml) and its MD5 hash.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.