logo

The Vendor Thread That Bit Back: How a Legitimate Tunneling Service Became a Phishing Vector

ID: abc8d1cf-250c-5c28-80c8-2d1e60c9fde3

STIX ID: report--abc8d1cf-250c-5c28-80c8-2d1e60c9fde3

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-28

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A vendor conversation thread was weaponized to deliver a malicious tunneling subdomain (a.pinggy.io) that passed SPF/DKIM/DMARC and attempted credential harvesting; the malicious link was tied to sandboxed PowerShell artifacts and an access token was exposed in the quoted history. IRONSCALES' Adaptive AI (Themis) detected link behavior, community signals, and content-context anomalies and quarantined the message across affected mailboxes within seconds; the report includes IOCs and recommended mitigations (audit tunneling services, revoke exposed tokens, deploy content-aware detection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.