The Button Text Was the Weapon: Unicode RTL Obfuscation Inside a DocuSign Lure
ID: be23d55b-3e70-55fc-bc9c-0892ad4d76d9
STIX ID: report--be23d55b-3e70-55fc-bc9c-0892ad4d76d9
Feed Name: IRONSCALES
A DocuSign-themed credential-harvesting campaign used pervasive U+200F right-to-left Unicode marks in email body and button labels to defeat automated classifiers, and laundered links through legitimate ESP tracking domains (Constant Contact and Mailjet) before landing on a Turkish-hosted credential harvest endpoint (sync.bursatasdunyasi.com, 78.135.106.170); the sender passed DMARC via DKIM using Amazon SES, indicating abuse of authorized marketing infrastructure. The report includes IOCs, the redirect chain, and recommended defenses (resolve full redirect chains, inspect control characters in display text, and treat DMARC pass as insufficient on its own).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
