The Meeting Invite That Knew Your Email Address
ID: fc9f7958-0e95-541d-823c-383084a84416
STIX ID: report--fc9f7958-0e95-541d-823c-383084a84416
Feed Name: IRONSCALES
A spearphishing campaign impersonated an internal Microsoft Teams meeting invite sent to a finance staff accountant; the malicious 'Join Meeting' button was wrapped by Microsoft SafeLinks but resolved to an AWS Lambda URL containing the recipient's base64-encoded email, indicating personalized credential harvesting. The report highlights impersonation (mismatched envelope sender), mixed legitimate links to create trust, the use of trusted cloud hosting to evade reputation checks, and recommends behavioral/AI-based detection and IOCs (domain, sender email, Lambda URL) for remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
