logo

The Mimecast Wrapper That Made a Phishing Link Look Safe

ID: ca071df1-d2c9-5a92-a5f5-1ad63000acc1

STIX ID: report--ca071df1-d2c9-5a92-a5f5-1ad63000acc1

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A targeted credential-phishing campaign impersonating a Dallas law firm used a one-day-old lookalike domain (crlaws.cam) hidden behind Mimecast SafeLinks rewriting and a fake “Powered by Microsoft Securely” badge to harvest credentials; the disposable domain went NXDOMAIN after use, SPF/DKIM/DMARC passed at the Mimecast relay while ARC preserved the upstream auth, and the report includes IOCs (domain, wrapped URL, relay IP, nameserver), analysis of the trust-chain manipulation, and actionable mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.