A Phishing Ticket Nobody Opened: How Autotask Became the Attack Vector
ID: fdc2bb97-042a-5cef-9bbb-d8e3ac0a3447
STIX ID: report--fdc2bb97-042a-5cef-9bbb-d8e3ac0a3447
Feed Name: IRONSCALES
A high-severity credential-harvesting campaign exploited Autotask's PSA mail relay to deliver ticket notifications that passed SPF/DKIM/DMARC and directed recipients to a genuine Autotask authentication page weaponized to capture credentials; behavioral analysis identified a content-subject mismatch (Slovak ticket body vs. English urgent subject) that protocol checks missed. The report provides indicators (8.34.161.203, DKIM selector 'autotask', weaponized authentication URLs), MITRE mappings (T1566.002, T1078, T1199), and concrete hardening recommendations for MSPs and clients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
