TL;DR Four mailboxes at a construction consulting firm received a document review request just after midnight UTC. Every authentication check passed, because the message was not spoofed: it left the mail system of a real insurance company whose account had been taken over. The Reply-To carried the same sender alias over a different, privacy-shielded domain, and the portal button pointed at a subdomain of an artist portfolio hosting service rather than any file-sharing brand. Themis scored it at 89 percent and all four mailboxes were remediated within about fifteen minutes.
Severity: High Credential-Harvesting Vendor-Email-Compromise Authenticated-Phishing Saas-Abuse Reply-To-Diversion MITRE: T1566.002 MITRE: T1586.002 MITRE: T1583.001 MITRE: T1583.006

A little after midnight UTC, four mailboxes at a construction consulting firm received the same message. The subject read "Request for review #-53D0X1". The sender alias read "DocShare". The body offered one button, an invitation to access and review documents that were waiting.

Nothing in the header was forged. SPF passed on the envelope sender, DKIM passed with a signature from the sending domain itself, DMARC passed with the visible sender aligned, and composite authentication scored the maximum. Every one of those results was correct, and the reason they were correct is the reason the case is worth writing up. The message genuinely came from the domain printed on it. That domain belongs to an insurance company that had nothing to do with the campaign.

Authentication Confirmed the Wrong Thing

There is a habit of reading a clean authentication block as a verdict on intent. It is a verdict on custody. RFC 7489 describes a mechanism for confirming that the domain in the visible sender authorized the message and that the signature holds. It has nothing to say about whether the human at the keyboard is the human who usually sits there.

Here the answer to that second question was no. The sending mailbox was a generic no-reply alias on a real insurance company's own mail system, and the campaign was being pushed out through it. That is vendor email compromise in its plainest form, and it inverts every reputation heuristic a gateway owns. There is no lookalike domain to catch, no fresh registration to age-check, no failed alignment to score. The infrastructure is clean because it is somebody else's, and that somebody has been paying into its reputation for years.

MITRE ATT&CK files this under compromising email accounts rather than acquiring them, and the distinction is the whole attack. Acquired infrastructure has to earn trust. Stolen infrastructure arrives with trust attached.

The Reply Path Went Somewhere Else Entirely

The visible sender had to stay genuine for the alignment to hold, so the attacker moved the part they actually needed into the field authentication does not evaluate. The reply address carried the same "DocShare" alias, so a preview pane and a reply window would show identical sender text, over a completely different domain: knkmg[.]com.

That domain is not a throwaway. WHOIS puts it at Dreamhost, registered a few years before the send, with registrant, administrative and technical contacts all replaced by a registrar privacy proxy service. No organization, no country, no operator. A domain old enough to defeat newness scoring and anonymous enough to defeat attribution, sitting in the one header field that never gets held to the standard the sending domain does.

The consequence is quiet. A recipient who found the button strange and replied to ask about it would have that question, their signature block, and their willingness to engage delivered to the attacker instead of the insurance company, under a sender name matching what they thought they were answering.

A Portfolio Host Serving a Document Portal

The call to action, an invitation to access and review the documents, pointed at hxxps://doc-share[.]carbonmade[.]com/. Carbonmade is a hosting platform for creative and artist portfolios. It has no document workflow product, no enterprise file sharing offering, and no business reason to be serving a corporate review portal to a construction firm.

That is exactly why it was chosen. The apex domain is legitimate and long-lived, the TLS certificate is valid and issued to the platform, there is no registration event to detect, and the attacker pays no reputation cost because the reputation is not theirs to burn. All they contributed was a subdomain label, and "doc-share" reads like a product to anyone glancing at a status bar. Automated link inspection returned a clean verdict. This is acquiring web services as ordinary campaign tooling, and the cheapest version is a free tier on a platform nobody has a blocklist entry for.

The tell survives anyway, as a mismatch of category rather than of string. A document review request should terminate on a document platform. Asking what business a host is actually in costs one lookup and no reputation feed at all.

See Your Risk: Calculate how many threats your SEG is missing

The Clean Links Were Part of the Costume

The payload link was not the only one in the body. Sitting alongside it were several genuine links to Microsoft's own phishing awareness material, real destinations resolving to Microsoft properties, dropped in as trust furniture.

It is a small, cynical piece of stagecraft. A message carrying security education links looks like it came from an organization that runs security education, and a scanner tallying destinations sees a body that is mostly reputable. Any control scoring a message on the proportion of harmless links can be tilted by adding harmless links. The signal that survives is the one destination that does not belong, not the ratio.

Vagueness Was the Pretext

The lure had no content to falsify. It named no project, no drawing set, no sender, and no originating company. It offered a reference number, "#-53D0X1", with a stray punctuation character wedged in front of it, the kind of formatting artifact real document systems do not produce. The reference resolved to nothing a recipient could check.

For a firm that reviews submittals, drawings and change documents as its actual work, that emptiness is close to camouflage. A vague review request looks like the twentieth one this week. The four targeted mailboxes were role-based aliases rather than personal addresses, and the recipient in the reported case sat in a project-delivery role with routine document authority. The 2024 Verizon Data Breach Investigations Report puts the median time from opening a phishing email to clicking at 21 seconds, which is not enough time to notice that a reference number refers to nothing.

How the Case Closed

Themis, the IRONSCALES Adaptive AI analyst, scored the message at 89 percent and applied two labels: credential theft and high-value recipient. The incident resolved automatically as phishing rather than being routed for manual triage, and all four affected mailboxes were remediated inside roughly fifteen minutes of delivery. No authentication signal contributed anything to that verdict, because there was no authentication signal to contribute. The evidence was the shape of the message: a first-contact sender in an unrelated industry, a reply path leaving that sender's domain, and a portal hosted somewhere with no relationship to documents. Closing that window quickly is the entire job of credential harvesting protection once prevention has been handed a message that passes every check.

What To Take From This Case

Compare the sending domain against the reply domain on every unexpected request, and treat divergence as a finding rather than a formatting quirk. Then ask what industry the landing host is in. Neither check needs threat intelligence, and both fire on this message while SPF, DKIM and DMARC stay silent. As both NIST and CISA phishing guidance frame it, authentication results open a content and context review instead of substituting for one. A perfect header block on a first-contact sender does not settle the question of who is typing. It is the last thing left that can be true while everything else is false.

Indicators of Compromise

TypeIndicatorContext
DomainWithheld (legitimate insurance company domain)Fully authenticated sending domain, SPF, DKIM and DMARC passing with composite authentication at maximum; a real business whose mailbox was abused, withheld as an innocent third party
EmailWithheld (no-reply alias on that same domain)From header address, a generic no-reply alias on the compromised business mail system
Domainknkmg[.]comReply-To diversion domain, registrar Dreamhost, registrant, administrative and technical contacts all replaced by a privacy proxy service, registered a few years before the send
Emailnoreply@knkmg[.]comReply-To address carrying the same "DocShare" alias as the From header
URLhxxps://doc-share[.]carbonmade[.]com/Call to action destination, a creative portfolio hosting platform subdomain posing as a document review portal, automated scan verdict clean
Hostdoc-share[.]carbonmade[.]comAttacker-supplied subdomain label on a long-lived legitimate apex domain with valid platform TLS
Subject"Request for review #-53D0X1"Lure subject with a malformed reference token, stray punctuation before the identifier, referring to no real document
Display NameDocShareGeneric file-sharing alias, identical on the From header and the reply path despite the domains differing
ArtifactGenuine Microsoft phishing awareness links in the bodyBenign decoy destinations present alongside the payload link

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing LinkT1566.002Document review lure delivering one credential-harvest link to four role-based mailboxes
Compromise Accounts: Email AccountsT1586.002Sent through a real insurance business's own mail system, producing full alignment with no spoofing
Acquire Infrastructure: DomainsT1583.001Aged, privacy-proxy-registered domain used only in the reply path, where alignment is never checked
Acquire Infrastructure: Web ServicesT1583.006Fake document portal on a portfolio SaaS subdomain, inheriting the platform's reputation and certificate

See You Next Time

When the header is flawless, stop reading the header. Back tomorrow with the next teardown.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Fake ShareFile Alert on a Real ShareFile LinkA shared-folder notification borrowed ShareFile's real brand domain, failed every authentication check at delivery.
The Phishing Link That Was Only an ImageFour mailboxes at a European plastics and packaging manufacturer got an Italian file-share notice from a logistics vendor they already worked with.
The Auth0 Developer Tenant That Passed Every Security Check (Because It Was Real)An attacker weaponized Auth0's free developer tenant to build a phishing chain that passed DKIM, DMARC, and every link scanner.
The Lab Result Notification That Every Security Check Approved (Because the Platform Was Real)A credential harvest targeting healthcare portal logins arrived through bridgeinteract.io, a legitimate HIPAA-adjacent patient engagement platform.
DMARC BestGuessPass: How a Malicious Domain Passed Every Auth Check and Still DeliveredA freshly registered domain with full SPF and DKIM passes exploited a missing DMARC record to earn Microsoft's bestguesspass verdict.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.