logo

Trusted, Signed, Still Malicious. Exploiting Custom Email Text to Bypass Security Controls

ID: f9e9053a-5b6f-5f14-8263-5704c097a4f1

STIX ID: report--f9e9053a-5b6f-5f14-8263-5704c097a4f1

Feed Name: Cofense Blog

Threat Score
60/100

Date Published: 2026-01-28

Date Updated: 2026-04-27

Author: Cofense

...
...

This report describes a campaign where attackers abuse legitimate services (e.g., Zoom, document sharing, Exchange Online redirection) by inserting phone-scam messages into user-visible text fields so that outgoing, legitimately-sent emails carry the malicious content; because the emails are resent without changing the From header and preserve SPF/DKIM/DMARC, they have been observed bypassing major secure email gateways and tricking recipients into engaging with the scam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.