Oh well that's fucking clever. A threat actor is sending out phishing emails pretending to be SendGrid, and explaining that all their emails will include "Support ICE" banners in order to trigger ragebait clicks through to the phishing kit.
Oh well that's fucking clever. A threat actor is sending out phishing emails pretending to be SendGrid, and explaining that all their emails will include "Support ICE" banners in order to trigger ragebait clicks through to the phishing kit.
@neurovagrant s/clever/evil/
I hate scumbags like this, but I have to have some respect for decent craft.
So here's the historical pDNS and domain data for sender domains in the headers of these emails from the samples I have.
SendGrid UPNs have been a bust so far, but guessing the attack isn't something to really write home about, but I'd like to see this group in particular inconvenienced for the ragebait aspect.
@neurovagrant i often find myself both disgusted at the depravity of some cybercriminals, yet impressed by their technical skill.