logo

Someone Filed a False Positive on This Azure TOAD Scam. Here's Why That's the Whole Point.

ID: d96e0a39-e229-5276-8f01-13351c320291

STIX ID: report--d96e0a39-e229-5276-8f01-13351c320291

Feed Name: IRONSCALES

Threat Score
65/100

Date Published: 2026-03-21

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

Attackers provisioned a real Azure subscription and configured Azure Monitor to send legitimate emails from [email protected] that contained a fabricated billing notice and unverified callback numbers; all authentication checks (SPF/DKIM/DMARC) passed and links pointed to portal.azure.com, so the message appeared authentic. The campaign uses Telephone-Oriented Attack Delivery (TOAD): there are no malicious links or attachments, only social engineering to get recipients to call attacker-controlled numbers, and it was marked a false positive by a human reviewer. The report urges auditing Azure alert rules, treating content-authentication mismatches as detection signals, training reviewers to verify callback numbers, and deploying behavioral AI to detect intent-based abuse of legitimate infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.