Authors
Kyle Eaton
Detection

Sublime’s Attack Spotlight series is designed to keep you informed of the email threat landscape by showing you real, in-the-wild attack samples, describing adversary tactics and techniques, and explaining how they’re detected. Sign up to receive these attack spotlights directly to your inbox.

Get a live demo to see how Sublime prevents these attacks.

Email provider: Google Workspace

Attack type: financial fraud




Last year, we published a blog about financial fraud attacks using YOPmail. What made those attacks most interesting wasn’t the fraud, it was that the attackers used YOPmail, an anonymous email service that doesn’t require user authentication. This meant we were able to get into the attacker’s account to see what they’ve been up to, no password required.

Recently, we found a different kind of attack that gave us similar insights into the history of the adversary. In this case, we found attacks featuring a recycled W-9 that offered up PDF revision histories of different financial fraud scams.

Attack email

Here’s an example email from one of the attacks:

There’s a lot of redaction, but here’s the flow the bottom to the top:

  1. Fabricated pre-invoice notification: The first message in this fully fabricated email thread is from the CPO/COO of ServiceNow. It sets up the premise that the target company has recently implemented a ServiceNow analytics solution and that an invoice will be sent soon. Major indicators of malicious intent are: 1) the message was sent from an executive, 2) the sender’s email address is the service-nowinc[.]com lookalike domain.
  2. Impersonated confirmation and routing: The second message is from an impersonated employee at the target company. They are confirming that the invoice is expected and tell ServiceNow to send it to the target of the attack.
  3. Fabricated “missing invoice” email: The third message loses the plot a bit and features “late payment” verbiage. This is a standard tactic in driving urgency, though the lack of timestamps in the fabricated thread means the target needs to assume there was a gap between messages two and three. Just like with message one, this is an impersonated ServiceNow employee with a service-nowinc[.]com email.
  4. Impersonated approval email from target company: The final message is a fake approval from the impersonated employee in message two that has been sent to the target of the attack. While the Display Name is a real employee, the message is sent from info@nuf.co[.]jp with the Reply-To address i@domainlify[.]net.

Indicators of AI

While investigating the attack, we determined with relative certainty that the thread was generated with AI. Within the HTML, we observed comments between each message of the fake thread. These appear to be remnants of an LLM prompt:

<!-- ── EMAIL 1: [Impersonated employee] approves ── -->
<!-- ── EMAIL 2: Stacy follows up ── -->
<!-- ── EMAIL 3: [Impersonated employee] replies to Stacy ── -->
<!-- ── EMAIL 4: Amit original invoice ── -->

Attachments

The fabricated thread contains two attachments. The first is a fake invoice that impersonates the billing vendor (ServiceNow) and aligns with the information in the attack email. It features a suspicious GO2BANK account account and asks for questions to be sent to the attacker controlled email gomez@service-nowinc[.]com:

The other attachment is a fake W-9 for the impersonated billing vendor. This is being used simply to increase believability, not as a payload:

Everything on this W-9 is publicly available information, making it easy for an attacker to create this form.

PDF attack history

While the W-9 was not a payload for the target, it did offer up interesting insights. PDFs contain a version history that can be sniffed out a few ways. In the case of this attack, we found that the W-9 was originally created for a “SCALED SOLUTIONS USA, LLC,” indicating that it had been used for a prior attack.

Using the versions within, we created an animated history of the PDF where you can see it start blank, get filled with Scaled Solutions information, and then get edited for the ServiceNow impersonation:

What makes this even more interesting is that during our investigation, we uncovered multiple other attacks using the same base “Scaled Solutions” PDF. In these similar attacks, we saw the same tactics (thread fabrication, financial urgency, fake invoice), but the W-9s were from a variety of impersonated vendors.

When we went through the revision histories of each of those W-9s, we found the same blank, scanned W-9 as the base revision, as well as the same “Scaled Solutions” information in the next set of revisions. This type of information can prove useful for detection engineers, threat intelligence analysts, threat researchers, and SOC teams performing investigations into threat actors.

Dig deeper at GrrCON

If you’re interested in learning how we investigated these attacks and analyzed their version histories, come to my “VIPs and Fake IDs: Investigating PDF Revisions” talk at GrrCON 2026 on Thurs., Sept. 24 at 4:30 p.m. ET.

Detection signals

Sublime's AI-powered detection engine detected this attack. Some of the top detection signals were:

  • Fabricated approval chain: Attack centers around an artificially (likely AI) constructed email thread that creates false legitimacy for a fraudulent payment.
  • Lookalike domain: Attack uses service-nowinc[.]com to impersonate legitimate vendor servicenow[.]com.
  • Impersonation with domain mismatch: The fabricated thread references a real executive at the target company, but the final message is sent from info@nuf.co[.]jp with the employee name as the Display Name. The Reply-To features the same Display Name and the email address i@domainlify[.]net.
  • Suspicious bank: GO2BANK is not used by major enterprises.
  • Urgency: Attack uses late payment notice to create time pressure.

ASA, Sublime’s Autonomous Security Analyst, flagged this email as malicious. Here is ASA’s analysis summary from the first example:

So long and thanks for all the crumbs

History-filled PDFs aside, thread hijacking and fabrication is an increasingly popular tactic in modern, tailored attacks. In the case of thread hijacking, a threat actor will compromise an inbox, find an existing thread, and then use it to deliver a realistic attack. In the case of the above attack, we saw a fabricated thread that was potentially built using a real email from a different attack as the template. This tactic can prove difficult for legacy email security solutions to detect, making a strong case for AI-powered detection from Sublime.

If you enjoyed this Attack Spotlight, be sure to check our blog every week for new blogs, subscribe to our RSS feed, or sign up for our monthly newsletter. Our newsletter covers the latest blogs, detections, product updates, and more.

Read more Attack Spotlights:

Share this post

Get the latest

Sublime releases, detections, blogs, events, and more directly to your inbox.

check
Thank you!

Thank you for reaching out.  A team member will get back to you shortly.

Oops! Something went wrong while submitting the form.