TL;DR A staff mailbox inside a healthcare staffing agency sent four colleagues a two-sentence follow-up asking whether they had seen a report. The send was genuinely internal, so authentication passed truthfully and the platform scored the sender as a known, low-risk, previously corresponding colleague. Every behavioral tell that normally exposes a compromised account was simply unavailable. The only lie in the message was its destination: two links, one labeled as a PDF, both resolved to a bare host on an obscure top-level domain serving a counterfeit document page.
Severity: High Internal Spearphishing Compromised Account Abuse Brand Impersonation Malicious Link MITRE: T1566.002 MITRE: T1078.004 MITRE: T1583.001 MITRE: T1534

Four mailboxes at a healthcare staffing agency received the same two-sentence note one afternoon. Wondering if you got the Page 3 report I sent last week, it read, sending it your way again. Please get back to me after you review it.

There was no attachment. No deadline, no invoice, no wire request, nothing that reads as pressure. The To line said undisclosed recipients and the real targets sat on Bcc, four colleagues at the same company, the copies landing within two seconds of each other.

And the sender was a coworker. Not a lookalike of a coworker, not a display name borrowed from the directory. The message came out of that person's own mailbox, on the organization's own domain, through the organization's own mail platform.

Nothing To Compare The Sender Against

Start with what the receiving platform saw when it scored the sender, because that is the whole case. The account was internal. It was not a first-time sender. It had corresponded with this recipient before and with the wider organization before. Its risk level came back low. No impersonation flag was raised, and correctly so, since nobody was impersonating anyone: the account really was the account it claimed to be.

Every control most teams lean on for compromised-account phishing keys on a boundary. First-time-sender logic asks whether this correspondent is new. External-sender banners ask whether the mail crossed the perimeter. Sender risk scoring asks how this address has behaved elsewhere. All three questions have an answer here, and all three answers are reassuring. The corpus of guidance on account takeover is largely written around the cross-organization case, where a compromised supplier or law firm mails in from outside and the defender still has a perimeter to reason about. Move the compromised account inside the directory and that reasoning has nothing to hold.

Authentication tells the same story, which is why it is a footnote rather than a finding. SPF passed, DKIM passed with a signature covering the organization's own domain, DMARC passed, and both ARC sets validated across the internal hop. None of that was forged. The mail genuinely came from an authorized sender for that domain, so a pass was the truthful result. This is where the usual advice misfires: no stricter DMARC posture would have changed anything, because enforcement policy governs mail that fails alignment, and this message was aligned. Authentication answered the question it exists to answer, and that question was the wrong one.

The record proves an authenticated send from that mailbox. It does not contain a login audit, a sign-in anomaly or an analyst confirmation of takeover, so the honest reading is an authenticated send from inside the organization, consistent with account takeover, and the right operational response is to treat the mailbox as compromised until proven otherwise.

A File Name Pointing At A Web Path

With no attachment and no sender anomaly, the entire attack lives in two hyperlinks. Their display text is the only theater in the message: the first reads Page 3, the second reads PAGE 3.PDF, formatted to look like a filename someone dragged into the body.

Both point at the same address, and it is not a file. It is a web path called /invite/ on a bare hostname, no subdomain, under the .qpon extension. A link that presents itself as a PDF and resolves to a directory path on a non-corporate host is the single cleanest signal in this case, and it survives every trust the sender carried, because it is a property of the destination rather than of the origin.

The host itself was built for the job. Registration was about nine weeks before the message went out, through a Hong Kong registrar, with the record updated five days after creation and DNSSEC left unsigned. Its two nameservers sit on a disposable numeric-label .xyz apex domain rather than any commercial DNS provider. The extension deserves a careful word: .qpon is obscure and rarely seen in business mail, which is precisely its value. Analyst blocklist instinct is pattern recognition trained on familiar strings, and an unfamiliar one does not fire it. That is not the same as the extension being new, and no age claim about it is warranted. The 2024 Verizon Data Breach Investigations Report puts the median time to click a phishing link at 21 seconds, which is not enough time to look up a top-level domain you have never seen.

See Your Risk: Calculate how many threats your SEG is missing

The Page Behind The Button

The landing page is a hand-built counterfeit of an Adobe document notification: a white card on grey, a large red Acrobat logo, a heading announcing a document is ready, a line stating that a secure Adobe document has been received and inviting a click to access it, a green padlock reassuring the visitor that the transfer is verified and secure, and one red call-to-action button. A copyright line sits in the footer.

What is not on that page matters as much as what is. There is no username field, no password field, no form of any kind. The first stage is a pure brand-impersonation interstitial with a single button, a common staging pattern in which the interstitial absorbs automated inspection and filters out anyone not committed enough to click again. Whatever sits behind the button was never captured, no credential prompt was observed, and no recipient is recorded as having entered anything. Adobe is a bystander throughout, and no Adobe domain, service or asset appears anywhere in this attack.

What Actually Caught It

Detection came from the payload and the language, because nothing else was available. The link was independently verdicted malicious. Themis, our Adaptive AI, returned 83 percent confidence with credential-theft and VIP-recipient labels, citing both the flagged link and an analysis of the message's wording and structure. That is a content and destination call, made in the complete absence of a sender signal.

Mitigation was quick. Three of the four copies were quarantined within about ten seconds of the incident opening, and the fourth returned an email-not-found result with no action taken. The incident closed as automatically resolved phishing, with no analyst reversal.

Both CISA phishing guidance and the NIST definition of phishing frame the threat as deception and elicited action rather than as files and infrastructure, which is exactly the framing an internal send requires. The 2023 FBI IC3 Internet Crime Report recorded roughly $2.9 billion in reported business email compromise losses, and losses at that scale come from real accounts saying things their owners never sent.

What To Take Into Monday

Internal mail needs the same link-level scrutiny as external mail. If your inspection pipeline treats same-domain traffic as pre-trusted, or your Google Workspace protections only score correspondents who arrive from outside, an attacker with one working set of credentials gets a clear run at everyone in the directory.

Teach the destination check rather than the sender check. Anchor text claiming a file extension while the href resolves to a directory path on an unfamiliar host is a durable, teachable tell that no amount of sender trust can launder. And when a staff mailbox sends something its owner did not write, work the account, not just the message: sessions, forwarding rules, delegates and credentials, before the next Bcc goes out.

Indicators of Compromise

TypeIndicatorContext
URLhxxps://nifty[.]qpon/invite/Destination of both hyperlinks. Verdicted malicious. Serves a counterfeit Adobe document-ready interstitial with one button and no input fields
Domainnifty[.]qponAttacker-registered landing host on an obscure top-level domain. Registered roughly nine weeks before the send via a Hong Kong registrar, updated five days after creation, DNSSEC unsigned
Domain2344234[.]xyzNameserver apex domain for the landing host. Disposable numeric-label DNS infrastructure, not a commercial provider
Anchor textPage 3 and PAGE 3.PDFTwo links, one dressed as a filename, both resolving to the same web directory path. The file-type claim versus destination mismatch is the strongest signal here
SubjectSent you the Page3 report againMundane follow-up framing referencing a report the recipients never received
Header patternTo: undisclosed-recipients:; with recipients on BccFour internal mailboxes addressed without visibility of each other, copies landing within two seconds
Sender profileInternal, not first-time, prior correspondence, low risk, no impersonation flagThe absence of any sender anomaly is the defining artifact, not a scoring oversight
Detection signalAdaptive AI confidence 83 percent, credential-theft and VIP-recipient labelsDriven by the link plus language and structure analysis, with no sender signal contributing

MITRE ATT&CK Mapping

TechniqueIDApplication
Phishing: Spearphishing LinkT1566.002Two body hyperlinks, one presented as a PDF filename, both resolving to the attacker's landing path
Internal SpearphishingT1534Mail sent from an account inside the target organization to colleagues on the same domain, inheriting directory standing and correspondence history
Valid Accounts: Cloud AccountsT1078.004An authorized Google Workspace mailbox in the organization's own tenant provided authenticated, truthfully aligned delivery
Acquire Infrastructure: DomainsT1583.001Purpose-registered bare host on an obscure top-level domain, pointed at throwaway numeric-label nameservers
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
One Brand's Artwork, A Different Brand's Landing PageAn e-invitation rendered with genuine artwork pulled live from the real brand's own CDN, including its tracking pixel.
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
The B2B Content Marketing Email That Borrowed a Brand, a Relay Allow-List, and a Security Vendor's Own URL WrapperA polished B2B research report offer used SelectHub branding, passed through an allow-listed mail relay at SCL -1.
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.