New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Virus Bulletin Q3 2026 report details phishing using DKIM-aligned senders, Amazon SES delivery, and real-time URL cloaking to evade email security and scanners.
Virus Bulletin's Q3 2026 testing found phishing campaigns delivered through trusted infrastructure like Amazon SES with DKIM-aligned sender domains. Samples included a German overdue-invoice lure redirecting to OpenSea crypto fraud and a Romanian BCR-branded PSD2 banking credential-theft campaign. Cloaking pages used hidden iframes, browser fingerprinting, and time-zone checks to show different content to scanners versus victims. Defenders are urged to inspect full redirect chains rather than attachments or initial URLs alone.
- DKIM-aligned senders and Amazon SES defeat reputation-based email filtering
- Cloaking pages fingerprint browsers and selectively show benign content to scanners
- Lures include antivirus renewals, overdue invoices, and PSD2 banking consent
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | 31-59-175-195.syd.nbn.aussiebb.net | of compromise (IoCs):- Type Indicator Description Hostname 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net Redirect infrastructure used in the antivirus renew |
| domain | eightindigostove.com | ssociated with the antivirus renewal phishing sample Domain eightindigostove[.]com Domain hosting the unsubscribe path in the antivirus rene |
| domain | loadswage.com | sed in the antivirus renewal scareware phishing flow Domain loadswage[.]com Redirect infrastructure associated with the antivirus ren |
| domain | moolaah.com | path in the antivirus renewal phishing sample Sender domain moolaah[.]com DKIM-aligned sender domain used for the cloaked overdue-p |
| domain | opensea.io | ing page used in the invoice phishing redirect chain Domain opensea[.]io Final destination reached after the cloaking and browser- |
| domain | web5-4s4c-online-garantibbva.vibtee.com | Pv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ Redirect destination in the Romanian PSD2 banking p |
| domain | website-2df62808.mvplineup.com | omain used for the cloaked overdue-payment invoice lure URL website-2df62808[.]mvplineup[.]com/audacity/underside First-stage cloaking page used in th |
| domain | xmasbrick.com | the cloaking and browser-fingerprinting stage Sender domain xmasbrick[.]com DKIM-aligned but unrelated sender domain used in the Roma |
| url | http://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF | nder domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the bankin |
Full article918 words · extracted from cybersecuritynews.com · click to collapse
Phishing is arriving via trusted email systems. Instead of using obvious malicious addresses, attackers send ordinary account alerts, invoices and renewal notices that lead victims into web-based traps.
The approach moves danger into a click path that can change in real time. A message may pass authentication, carry no harmful file and still guide a recipient through redirects, browser tests and deceptive pages.
Its Q3 2026 testing encountered phishing samples using this model. The campaigns paired familiar themes with infrastructure designed to hide the final destination from simple checks.
The impact goes beyond one lure. A fake antivirus renewal can seek payment details, an overdue invoice can push a victim toward crypto-related fraud, and a banking notice can target credentials.
Virus Bulletin said in a report shared with Cyber Security News (CSN) that each uses a believable prompt and a destination that may behave differently for security scanners than for a person.
New Phishing Attacks Use Trusted Email Infrastructure
One August example used a German overdue-payment notice that appeared to request opening a “Mahnschreiben,” or payment reminder.
It was delivered through Amazon Simple Email Service from a domain whose DKIM signature aligned, giving the message technical signs many filters associate with legitimate mail.
.webp)
There was no attachment to inspect. The link loaded a page with decoy content, hidden text, a tiny iframe and scrambled code.
It collected browser and time-zone details, then sent a hidden request before leading to OpenSea during analysis, pointing to a cloaked crypto or NFT fraud route rather than malware delivery.
That sequence illustrates why trusted cloud services hide phishing so effectively. The delivery platform can be genuine, the sending domain can authenticate correctly, and the first page can look harmless when inspected outside the intended browser, time or location.
A separate Romanian-language campaign copied BCR S.A. branding and claimed a PSD2 consent renewal was required before banking access would be restricted.
It used a DKIM-aligned but unrelated sender and an IPv6-mapped address in the link, a format that can make a destination harder to assess automatically. The link resolved through another redirect before reaching Google during verification.
.webp)
Researchers assessed the operation as credential theft, while noting that the active page may have been expired, cloaked or configured to show benign content selectively. That uncertainty makes simple reputation lookups and one-time scans less reliable.
Why Familiar Lures Still Work
The samples did not need a new malware family to cause harm. They used familiar fears: an infected device, an unpaid bill, blocked banking access or a subscription about to end.
A Dutch-language renewal email, for example, warned of “631 dangerous viruses,” threatened account closure and offered a discount to hurry a decision.
These messages exploit a gap between technical trust and human trust. Passing SPF, DKIM or DMARC shows that a message was authorised by a domain, but it does not prove that the underlying business request is honest.
The same concern appeared in Amazon SES phishing delivery, where authenticated mail was used to avoid reputation-based blocking.
Recipients should avoid opening invoices, renewal pages or banking updates through unexpected email links, even when the sender appears legitimate.
.webp)
They should reach the claimed service by entering its known address or using a saved application, then verify any alert from inside the account. This pause can break a redirect chain before credentials or payment data are entered.
For defenders, the report underscores the need to examine the full click path rather than only an email’s attachment status or initial URL.
Controls should inspect redirects, unusual IP-based links, browser fingerprinting and post-load behaviour, while teams should treat authentication as one signal among many. Trusted Google service abuse shows how multi-stage routes can make an early link look safe.
Security teams can hunt for the supplied indicators, review messages imitating payment, banking or renewal workflows, and warn staff about urgent requests.
The broader lesson aligns with blob URL phishing techniques: attackers increasingly place harmful content later in the journey, where conventional email checks have less visibility.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Hostname | 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net | Redirect infrastructure used in the antivirus renewal scareware phishing flow |
| Domain | loadswage[.]com | Redirect infrastructure associated with the antivirus renewal phishing sample |
| Domain | eightindigostove[.]com | Domain hosting the unsubscribe path in the antivirus renewal phishing sample |
| Sender domain | moolaah[.]com | DKIM-aligned sender domain used for the cloaked overdue-payment invoice lure |
| URL | website-2df62808[.]mvplineup[.]com/audacity/underside | First-stage cloaking page used in the invoice phishing redirect chain |
| Domain | opensea[.]io | Final destination reached after the cloaking and browser-fingerprinting stage |
| Sender domain | xmasbrick[.]com | DKIM-aligned but unrelated sender domain used in the Romanian banking phishing email |
| URL | hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 | IPv6-mapped IP-literal URL embedded in the banking phishing message |
| IPv4 address | 103[.]193[.]179[.]223 | IPv4 address represented by the IPv6-mapped URL notation |
| URL | web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/ | Redirect destination in the Romanian PSD2 banking phishing chain |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/new-phishing-attacks/