The Mimecast Wrapper That Made a Phishing Link Look Safe
ID: ca071df1-d2c9-5a92-a5f5-1ad63000acc1
STIX ID: report--ca071df1-d2c9-5a92-a5f5-1ad63000acc1
Feed Name: IRONSCALES
A targeted credential-phishing campaign impersonating a Dallas law firm used a one-day-old lookalike domain (crlaws.cam) hidden behind Mimecast SafeLinks rewriting and a fake “Powered by Microsoft Securely” badge to harvest credentials; the disposable domain went NXDOMAIN after use, SPF/DKIM/DMARC passed at the Mimecast relay while ARC preserved the upstream auth, and the report includes IOCs (domain, wrapped URL, relay IP, nameserver), analysis of the trust-chain manipulation, and actionable mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
