Someone Filed a False Positive on This Azure TOAD Scam. Here's Why That's the Whole Point.
ID: d96e0a39-e229-5276-8f01-13351c320291
STIX ID: report--d96e0a39-e229-5276-8f01-13351c320291
Feed Name: IRONSCALES
Attackers provisioned a real Azure subscription and configured Azure Monitor to send legitimate emails from [email protected] that contained a fabricated billing notice and unverified callback numbers; all authentication checks (SPF/DKIM/DMARC) passed and links pointed to portal.azure.com, so the message appeared authentic. The campaign uses Telephone-Oriented Attack Delivery (TOAD): there are no malicious links or attachments, only social engineering to get recipients to call attacker-controlled numbers, and it was marked a false positive by a human reviewer. The report urges auditing Azure alert rules, treating content-authentication mismatches as detection signals, training reviewers to verify callback numbers, and deploying behavioral AI to detect intent-based abuse of legitimate infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
