logo

The .com That Wasn't the .org: TLD Confusion in a Payroll Email With an Empty Body

ID: b98ebb30-0d86-5d2b-aed3-18ab2ce435b6

STIX ID: report--b98ebb30-0d86-5d2b-aed3-18ab2ce435b6

Feed Name: IRONSCALES

Threat Score
45/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: [email protected] (Audian Paxson)

...
...

A phishing campaign impersonated Grid Alternatives by sending an empty email with the subject 'Annual Salary wages and Employer Provided Benefits' from the lookalike domain gridalternatives.com (registered 2006). The message contained a clean 9 KB ODT attachment (generated by Pandoc) with no macros or links; DKIM signed by a provisioned M365 tenant passed, SPF for the .com domain returned NONE, ARC passed at a Google hop, and the relay IP was 192.3.7.3 (ColoCrossing). The report concludes the attack relied on TLD confusion and a benign-looking attachment as a reconnaissance or trust-building step rather than an immediate technical exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.