Observed IOC: Malicious root domains in body links
Observed IOC: Malicious URLs in body links
Open redirect: Cartoon Network
Open redirect: giving.lluh.org
Open redirect (go2.aspx) leading to Microsoft credential phishing
Open Redirect: Google domain with /url path and suspicious indicators
Open redirect: marketing.edinburghairport.com
Open redirect: people.anuneo.com
Open redirect: slubnaglowie.pl
Open redirect: typedrawers.com
Outlook hyperlink bypass: left-to-right mark (LRM) in base HTML tag
PDF attachment with Google (AE) redirecting to a php or zip file
PhaaS: Impact Solutions (Impact Vector Suite)
Potential prompt injection attack in body HTML
QR Code with suspicious indicators
Reconnaissance: All recipients cc/bcc'd or undisclosed
Reconnaissance: Email address harvesting attempt
Reconnaissance: Empty message from uncommon sender
Reconnaissance: Fake real estate inquiry with empty body
Reconnaissance: Hotel booking reply-to redirect
Reconnaissance: Large unknown recipient list
Reconnaissance: Short generic greeting message
Recruitee Infrastructure Abuse
Request for Quote or Purchase (RFQ|RFP) with HTML smuggling attachment
Request for Quote or Purchase (RFQ|RFP) with suspicious sender or recipient pattern
Salesforce infrastructure abuse
Scam: Fake estate sale offering welding equipment and tools
Scam soliciting employer review/rating
Self-sender with copy/paste instructions and suspicious domains (French/Français)
Self-sent fake PDF attachment with misleading link
Service abuse: Adobe legitimate domain with document approval language
Service abuse: Amazon invitation with suspected callback phishing
Service abuse: Apple TestFlight with suspicious developer reference
Service abuse: AppSheet infrastructure with suspicious indicators
Service abuse: AWS SNS callback scam impersonation
Service abuse: Behance document sharing with suspicious language
Service Abuse: Box file sharing with credential phishing intent
Service abuse: Callback phishing via Microsoft Teams invite
Service abuse: Cisco secure email service with financial request
Service abuse: Citrix ShareFile impersonation via Outlook plugin
Service abuse: Demio notifications with suspicious content patterns
Service abuse: DocSend share from an unsolicited reply-to address
Service abuse: DocSend share from newly registered domain
Service abuse: DocuSign notification with suspicious sender or document name
Service abuse: DocuSign share from an unsolicited reply-to address