Virus Bulletin Q3 2026 VBSpam Test Exposes Phishing via DKIM-Aligned Senders, Amazon SES, and Multi-Stage URL Cloaking
Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) details phishing campaigns that abuse trusted email infrastructure (DKIM-aligned domains, Amazon SES) and post-click evasion (redirect chains, browser-fingerprinting gates, hidden POST requests,…
Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) found phishing campaigns delivered through trusted infrastructure, including Amazon SES with DKIM-aligned sender domains, defeating reputation-based email filtering. Malicious activity shifted beyond the email itself to post-click evasion: redirect chains, browser-fingerprinting gates, hidden iframes, hidden POST requests, and time-zone checks that selectively show benign content to scanners and malicious content to victims. Documented lures include a Dutch McAfee/TotalAV scareware antivirus-renewal scam; a German overdue-invoice lure delivered via Amazon SES from DKIM-aligned moolaah.com redirecting to OpenSea/Web3 crypto fraud; and a Romanian BCR-branded PSD2 banking credential-theft campaign embedding IPv6-mapped URLs that resolve to 103.193.179.223, evading simple URL extraction and reputation checks. Product results diverged sharply: Net at Work NoSpamProxy ranked first with a 99.995 score, while open-source Rspamd caught only 62.55% of phishing mail. Defenders are urged to inspect full redirect chains rather than attachments or initial URLs alone.
- Source: Virus Bulletin Q3 2026 VBSpam test, identified as AMTSO-LS1-TP207, reported 2026-09-15
- Phishers abused DKIM-aligned sender domains and Amazon SES delivery to defeat reputation-based email filtering
- Cloaking techniques include hidden iframes, browser fingerprinting, time-zone checks, redirect chains, and hidden POST requests
- German overdue-invoice lure delivered via Amazon SES from DKIM-aligned moolaah.com redirected to OpenSea/Web3 crypto fraud
- Romanian BCR-branded PSD2 credential-phishing campaign used IPv6-mapped URLs resolving to 103.193.179.223 to evade URL extraction and reputation checks
- Dutch McAfee/TotalAV scareware antivirus-renewal scam documented as another lure
- Net at Work NoSpamProxy ranked first with a 99.995 score; open-source Rspamd caught only 62.55% of phishing mail
- Recommendation: inspect full redirect chains rather than attachments or initial URLs alone
Coverage timelineoldest first · each row is one article
- · 1d agoNew Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools
Cyber Security News· 45
Virus Bulletin Q3 2026 report details phishing using DKIM-aligned senders, Amazon SES delivery, and real-time URL cloaking to evade email security and scanners.
- · 1d agoPhishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters
GBHackers· 45
VBSpam Q3 2026 test shows phishers abusing DKIM-aligned domains, Amazon SES, and multi-stage URL cloaking to defeat email filters.