logo

Three Google Domains, One Redirect Chain, and a Turkish Landing Page

ID: f6d6b718-3c5d-50b3-a955-67dd8176f7eb

STIX ID: report--f6d6b718-3c5d-50b3-a955-67dd8176f7eb

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-05-30

Date Updated: 2026-05-30

Author: [email protected] (Audian Paxson)

...
...

A high-severity phishing sample delivered via Amazon SES injected a forged “Revise Now” CTA into a legitimate-looking forwarded thread from a UK financial firm; the CTA used a four-hop redirect chain that passed through three Google-owned redirect domains before resolving to an unrelated Turkish domain (mgokurumsal.com.tr). The report highlights template-injection to borrow credibility, how multi-hop trusted redirects evade link scanners, full SES authentication despite first-time sender risk, provides IoCs (sending domain, redirect hops, final destination, invoice reference), and maps the attack to MITRE techniques for phishing, malicious links, and masquerading.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.