logo

Custom-Crafted, Qantas-Spoofing Emails Target Australian Victims

ID: 1150f08e-8b96-5a8f-a908-b1ef07ae5f7e

STIX ID: report--1150f08e-8b96-5a8f-a908-b1ef07ae5f7e

Feed Name: Cofense Blog

Date Published: 2025-04-23

Date Updated: 2026-04-27

Author: Cofense

...
...

A credential-phishing campaign spoofing Qantas marketing emails targeted primarily Australian employees, bypassing multiple SEGs (Microsoft ATP, Proofpoint, Mimecast) to drive victims to short-lived phishing sites sharing an “auth/auhs1” path. The emails closely mimicked Qantas branding and included unsubscribe headers (subscriptions.pstmrk.it) to boost legitimacy. The phishing flow collected contact details and DOB before soliciting credit card data and simulating MFA, indicating a financially motivated operation with potential for follow-on attacks using harvested PII.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.