The Email That Shipped With Its Template Tokens Still In It (And Still Worked)
ID: dedda80a-c19d-5d5b-81af-5fa31189e6fa
STIX ID: report--dedda80a-c19d-5d5b-81af-5fa31189e6fa
Feed Name: IRONSCALES
A high-risk phishing campaign impersonated an Oracle NetSuite voicemail to target a finance distribution alias; despite broken mail-merge tokens in the subject, the message passed SPF/DKIM via Amazon SES and was delivered with a low spam score. The PLAY NOW button began at a Wix subdomain and traversed MailerSend and Mailjet tracking redirects to a 27-day-old domain (dapteknik.com) and a geo-gated 403, evading automated scanners. Themis/IRONSCALES flagged the link and quarantined affected mailboxes; IOCs (domains, URLs, sender IP) and remediation recommendations (domain-age signals, DMARC enforcement, awareness training) are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
