logo

The Datadog Alert That Came From the Wrong Domain: Authenticated Brand Impersonation With All Links Pointing to Real Infrastructure

ID: eeed2608-5663-5fcc-8aa0-c66991fb3bb7

STIX ID: report--eeed2608-5663-5fcc-8aa0-c66991fb3bb7

Feed Name: IRONSCALES

Threat Score
45/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: [email protected] (Audian Paxson)

...
...

**Executive Summary:** A spear-phishing email impersonated Datadog using the lookalike domain dtdg.co that passed SPF/DKIM/DMARC and sent via SendGrid; all action links resolved to the legitimate app.datadoghq.com and the message contained an open-tracking pixel, while WHOIS records for the domain showed no public registrant. The report provides IOCs (sending domain, sender address, sending IP, SPF/DKIM selector, SendGrid subdomain), maps the attack to MITRE techniques (domain acquisition, spearphishing link, masquerading), and assesses the tactic as medium risk because the message builds trust for likely future malicious follow-ups despite lacking immediate credential harvesting or malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.