The Zoho Sign Request That Passed Every Check Except the Reply-To: Government Impersonation via E-Sign Infrastructure
ID: d218cb19-5053-5c9f-b91c-2970ddfb563c
STIX ID: report--d218cb19-5053-5c9f-b91c-2970ddfb563c
Feed Name: IRONSCALES
Threat Score
A high-severity phishing campaign abused Zoho Sign's authenticated delivery to send convincing document-signing requests that used a legitimate Zoho sender and links but contained a deceptive Reply-To/in-message sender ([email protected]) tied to an unverifiable domain; the report provides IOCs, behavioral detection rationale, and MITRE mappings highlighting credential harvesting and impersonation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
