No SPF. No DKIM. No DMARC. No Problem (For the Attacker).
ID: fea4e42f-3a68-5e8b-a1d1-ab0a0367ce3a
STIX ID: report--fea4e42f-3a68-5e8b-a1d1-ab0a0367ce3a
Feed Name: IRONSCALES
**Phishing campaign — SharePoint-themed QR code credential theft:** An email impersonating an internal SharePoint notification (display name: mySharePointDrive-id:JSENUL8JVCKET0E) was sent from [email protected] via a FireVPS-RDP host (198.7.56.52) and a Polish Exim relay (mx.s5.masternet.pl). The message lacked SPF/DKIM/DMARC, contained malformed financial content and a QR code plus Microsoft short links displayed as 'Outlook for iOS', and targeted finance personnel to harvest credentials; the report provides IOCs, MITRE mappings, and mitigation steps including QR scanning inspection, stricter handling of zero-authentication senders, and user verification practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
