logo

No SPF. No DKIM. No DMARC. No Problem (For the Attacker).

ID: fea4e42f-3a68-5e8b-a1d1-ab0a0367ce3a

STIX ID: report--fea4e42f-3a68-5e8b-a1d1-ab0a0367ce3a

Feed Name: IRONSCALES

Threat Score
70/100

Date Published: 2026-03-28

Date Updated: 2026-04-28

Author: [email protected] (Audian Paxson)

...
...

**Phishing campaign — SharePoint-themed QR code credential theft:** An email impersonating an internal SharePoint notification (display name: mySharePointDrive-id:JSENUL8JVCKET0E) was sent from [email protected] via a FireVPS-RDP host (198.7.56.52) and a Polish Exim relay (mx.s5.masternet.pl). The message lacked SPF/DKIM/DMARC, contained malformed financial content and a QR code plus Microsoft short links displayed as 'Outlook for iOS', and targeted finance personnel to harvest credentials; the report provides IOCs, MITRE mappings, and mitigation steps including QR scanning inspection, stricter handling of zero-authentication senders, and user verification practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.