ZeroHour
Story · 2 sources · 2 articlesfirst updated ()1

Virus Bulletin Q3 2026 VBSpam Test Exposes Phishing via DKIM-Aligned Senders, Amazon SES, and Multi-Stage URL Cloaking

mediumPhishing & fraudexploited in the wildimportance 45
What's new: First merged summary for this story; establishes baseline by combining two same-day reports (Cyber Security News and GBHackers, 2026-09-15) on the Virus Bulletin Q3 2026 VBSpam test. Reports agree on core findings; GBHackers adds the test ID (AMTSO-LS1-TP207), the moolaah.com sender domain, the IPv6-mapped URL/IP detail, and product scores, while Cyber Security News adds the OpenSea redirect…
Merged summary · glm-5.3 · rewritten as coverage arrives

Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) details phishing campaigns that abuse trusted email infrastructure (DKIM-aligned domains, Amazon SES) and post-click evasion (redirect chains, browser-fingerprinting gates, hidden POST requests,…

Virus Bulletin's Q3 2026 VBSpam test (AMTSO-LS1-TP207) found phishing campaigns delivered through trusted infrastructure, including Amazon SES with DKIM-aligned sender domains, defeating reputation-based email filtering. Malicious activity shifted beyond the email itself to post-click evasion: redirect chains, browser-fingerprinting gates, hidden iframes, hidden POST requests, and time-zone checks that selectively show benign content to scanners and malicious content to victims. Documented lures include a Dutch McAfee/TotalAV scareware antivirus-renewal scam; a German overdue-invoice lure delivered via Amazon SES from DKIM-aligned moolaah.com redirecting to OpenSea/Web3 crypto fraud; and a Romanian BCR-branded PSD2 banking credential-theft campaign embedding IPv6-mapped URLs that resolve to 103.193.179.223, evading simple URL extraction and reputation checks. Product results diverged sharply: Net at Work NoSpamProxy ranked first with a 99.995 score, while open-source Rspamd caught only 62.55% of phishing mail. Defenders are urged to inspect full redirect chains rather than attachments or initial URLs alone.

  • Source: Virus Bulletin Q3 2026 VBSpam test, identified as AMTSO-LS1-TP207, reported 2026-09-15
  • Phishers abused DKIM-aligned sender domains and Amazon SES delivery to defeat reputation-based email filtering
  • Cloaking techniques include hidden iframes, browser fingerprinting, time-zone checks, redirect chains, and hidden POST requests
  • German overdue-invoice lure delivered via Amazon SES from DKIM-aligned moolaah.com redirected to OpenSea/Web3 crypto fraud
  • Romanian BCR-branded PSD2 credential-phishing campaign used IPv6-mapped URLs resolving to 103.193.179.223 to evade URL extraction and reputation checks
  • Dutch McAfee/TotalAV scareware antivirus-renewal scam documented as another lure
  • Net at Work NoSpamProxy ranked first with a 99.995 score; open-source Rspamd caught only 62.55% of phishing mail
  • Recommendation: inspect full redirect chains rather than attachments or initial URLs alone

Coverage timeline

  1. · 1d ago
    Cyber Security News· 45
    New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools

    Virus Bulletin Q3 2026 report details phishing using DKIM-aligned senders, Amazon SES delivery, and real-time URL cloaking to evade email security and scanners.

  2. · 1d ago
    GBHackers· 45
    Phishing Attacks Abuse Trusted Email Infrastructure and URL Cloaking to Evade Security Filters

    VBSpam Q3 2026 test shows phishers abusing DKIM-aligned domains, Amazon SES, and multi-stage URL cloaking to defeat email filters.