TL;DR A message stamped with the display name Indictment Notice reached finance staff at a consumer products manufacturer, posing as a COURT NOTICE with a ten-day hearing deadline. It came from a randomized outlook.com throwaway account, failed SPF, DKIM, DMARC, and ARC, yet still landed through a legitimate Barracuda relay. Replies diverted to a privacy-shielded China-registered domain, and a Related Documents link pointed at a ZIP hosted on Google Cloud Storage. The archive was never verified, but an explicit instruction to forward it internally to finance marked the intent.
Severity: Medium Impersonation Malware Delivery Cloud Service Abuse MITRE: T1566.002 MITRE: T1656 MITRE: T1204.001 MITRE: T1585.001 MITRE: T1102.002

A finance-department executive at an India-based consumer products manufacturer opened a message stamped with the display name "Indictment Notice." The subject read like a legal order. The body named the executive's own company directly, invoked a court hearing scheduled ten days out, and pointed at a set of "Related Documents." Then it closed with the part that gives the whole scheme away: share this information internally with the finance department.

Legal authorities do not ask you to redistribute their filings to your accounts-payable team. Attackers do, because finance is where the money and the fear both live.

The From address behind that ominous display name was afngjfnzjyasb@outlook[.]com. A random smear of letters on a free consumer webmail account. No tribunal, no docket, no law firm. Just a throwaway mailbox dressed up with a frightening label and aimed at a high-value internal team.

A Legal Threat With a Ten-Day Clock

The pretext is old, but it still works because it pairs authority with a deadline. A "COURT NOTICE" from an unnamed legal body carries implied consequences, and a ten-day hearing window manufactures urgency without demanding an immediate wire. That patience is the point. The message does not ask the reader to pay anything, so it slips past the reflex that a straight payment demand would trigger. It asks only that the reader open a document and pass it along.

Naming the target company directly does the rest. Generic spam addresses "Dear Customer." This message addressed the organization by name, which reads as research, and research reads as legitimacy. Once a recipient believes the sender knows exactly who they are, the odd sender address and the broken formatting get explained away.

The Delivery Chain Failed Every Check and Landed Anyway

Authentication on this message was a clean sweep of failures. SPF returned softfail, the sending IP discouraged rather than authorized. DKIM failed on a body-hash mismatch against header.d=outlook.com. DMARC failed too, but the outlook.com policy sits at p=none, so nothing enforced the failure. Even ARC, the chain meant to preserve trust decisions across relays, came back cv=fail.

The message still reached three mailboxes at the target, one of them via an internal forward. It traveled through a legitimate Barracuda Email Security Service relay at 209.222.82[.]49, a shared gateway hop rather than attacker infrastructure. That legitimate hop is the cover. Reputation attached to a mainstream security relay helps a message keep moving even when its own signatures are worthless. Authentication verdicts are only ever as strong as the weakest system still willing to pass the message forward.

The replies told the real story. The visible sender was an outlook.com address, but the Reply-To diverted to hmwdj[.]com, an unrelated, privacy-shielded domain registered through a China-based registrar and bearing no connection to the sender a reader could see. Anyone who hit reply with a nervous question would have their message captured off-platform, on infrastructure the visible sender never controlled.

The Payload Nobody Could Confirm

The "Related Documents" link did not point at a court portal. It resolved to a ZIP archive hosted on storage.googleapis[.]com, Google Cloud Storage. Parking attacker-supplied files on a major cloud platform is a deliberate reputation-borrowing move. The host belongs to Google, it resolves cleanly, and the reputation filters that would block an obscure server wave it straight through.

Here is the honest part: we do not know what was in that archive. The link scanned "clean," but the SOC flagged that verdict as potentially lagging and recommended sandbox detonation before anyone trusted it. The contents were never verified, so this is not a malware claim. It is something arguably more useful. A ZIP whose contents are unconfirmed, delivered by a broken-auth throwaway account impersonating a court, carrying an explicit instruction to forward it to finance, is hostile on structure alone. You do not need to detonate the payload to know the envelope is lying.

See Your Risk: Calculate how many threats your SEG is missing

Mapping to MITRE ATT&CK

The tradecraft maps cleanly to a handful of techniques in the MITRE ATT&CK framework:

  • T1566.002 Spearphishing Link covers the core delivery, a socially engineered message whose payload is a link to a cloud-hosted archive.
  • T1656 Impersonation covers the legal-authority disguise, a "COURT NOTICE" issued by a body that does not exist.
  • T1204.001 User Execution: Malicious Link covers the human step the whole message was engineered to produce, a click followed by an internal forward.

Two supporting behaviors round out the picture: the disposable outlook.com mailbox reflects an attacker standing up a throwaway sending account, and the Google Cloud Storage stage reflects the abuse of a legitimate web service to host and hand over attacker content.

Indicators of Compromise

TypeIndicatorContext
Sender emailafngjfnzjyasb@outlook[.]comThrowaway consumer webmail account, randomized local-part, display name "Indictment Notice"
Reply-To domainhmwdj[.]comPrivacy-shielded, China-registered diversion domain, unrelated to the visible sender
URLhxxps://storage.googleapis[.]com/ydhhs/[numeric-id][.]zipZIP archive on Google Cloud Storage, contents unverified, clean scan flagged as unreliable
Sending IP209.222.82[.]49Legitimate Barracuda ESS relay hop, not attacker infrastructure

Reading Intent, Not Just Signatures

Signature and reputation checks were never going to catch this. The sending relay is legitimate, the cloud host is Google, and the payload verdict came back clean. Every server-level signal a gateway leans on was either broken in a way that did not stop delivery or legitimate in a way that actively helped it. Detection has to read intent.

That is where IRONSCALES adds a layer static gateways miss. Themis, the Adaptive AI analyst on the IRONSCALES platform, weighs the relationship between a legal-authority pretext, a randomized free-webmail sender, a mismatched foreign Reply-To, and a cloud-hosted archive the way a human analyst would, and flags the impersonation even when SPF, DKIM, and DMARC results amount to noise. Link-focused controls like advanced malware and URL attack protection then treat an unverified cloud-hosted ZIP as guilty until sandboxed, rather than trusting a lagging clean verdict. That signal comes from 35,000+ security professionals across 17,000+ organizations, which is how a novel throwaway account gets recognized as phishing on first contact.

The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and clocks the median time to click a phishing link at 21 seconds. It also names pretexting, mostly business email compromise, as the top social-engineering incident type, with a median transaction near 50,000 dollars, which is precisely why aiming this lure at finance was deliberate. The Microsoft Digital Defense Report 2024 documents the same migration toward abusing trusted services, cloud storage among them, rather than breaking them. And the FBI's 2023 Internet Crime Report has long ranked business and identity impersonation among the costliest fraud categories, the exact lever this campaign pulled.

The Takeaway

A court does not email a ZIP file from a consumer webmail account and ask you to forward it to accounting. Strip away the legal-authority costume and this message is a stranger with a broken ID handing your finance team a sealed box and telling them to open it together. The defense is to treat the pretext as decoration and inspect the mechanics: who actually sent it, where a reply would land, and where a link truly resolves. CISA's guidance on recognizing and stopping phishing early is a solid reference for building that reflex across a finance team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Patent Filing Deadline That Came From the Wrong DomainAttackers impersonated an Indian IP law firm using a one-character domain swap (.co vs .sg), sent statutory patent filing forms to the exact right people.
Credential Phish by Day, Remote-Access Trojan by NightA payment-themed notification carried a DocuSign logo and one blue button.
The CEO's Name Was Real. The Mailjet Account Behind It Wasn't.An attacker impersonated the CEO of an email security company using a legitimate Mailjet ESP account with full SPF/DKIM pass.
The Phishing Link Lived on a Domain That Didn't Exist Nine Hours EarlierA compromised university student account sent a phishing email that passed SPF, DKIM, and DMARC.
The Health Spending Account Alert That Rode a Benefits Administrator's Own InfrastructureAn Anthem-branded spending account notification routed through a legitimate benefits administrator's redirect infrastructure.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.