logo

A Phishing Ticket Nobody Opened: How Autotask Became the Attack Vector

ID: fdc2bb97-042a-5cef-9bbb-d8e3ac0a3447

STIX ID: report--fdc2bb97-042a-5cef-9bbb-d8e3ac0a3447

Feed Name: IRONSCALES

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

A high-severity credential-harvesting campaign exploited Autotask's PSA mail relay to deliver ticket notifications that passed SPF/DKIM/DMARC and directed recipients to a genuine Autotask authentication page weaponized to capture credentials; behavioral analysis identified a content-subject mismatch (Slovak ticket body vs. English urgent subject) that protocol checks missed. The report provides indicators (8.34.161.203, DKIM selector 'autotask', weaponized authentication URLs), MITRE mappings (T1566.002, T1078, T1199), and concrete hardening recommendations for MSPs and clients.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.