Table of Contents
The attacker wrote one thing: a picture. A revenue and growth executive at a commercial insurance company received a reply carrying a single embedded image, roughly 764 by 451 pixels, styled as a completed e-signature notice with the words "Download completed documents" across it. There was no covering sentence, no greeting, no attachment, and no explicit request. Below the image, separated by a run of empty paragraphs, sat a genuine litigation thread: real correspondence between two law firms working through deposition scheduling in an active matter, consistent in tone, on topic, and closing with a complete signature block. Every verifiable statement in that message was true. The image was the only part the attacker contributed, and the only part that mattered.
An image with no sentence around it
Strip the quoted history away and there is almost nothing left to analyze. Body copy is where intent usually leaks: urgency, a payment instruction, a credential ask, awkward phrasing. Here the lure text, branding, and call to action were all baked into pixels. The attachment scanner rated the embedded file medium risk on the strength of what it depicted rather than what it contained, since it carried no macros, no script, and no executable content. A picture of a document-delivery notice is not malware.
That leaves the recipient's judgment as the primary control. The 2024 Verizon Data Breach Investigations Report puts the median time from opening a phishing email to clicking a link at 21 seconds. A single unexplained image at the top of a thread you recognize is a fast click, not a considered one.
The link pointed at a rental, not a landing page
The image was wrapped in exactly one link: hxxp://capitolccmpm[.]com/. Follow it and you do not arrive at a credential form or a cloned portal. You arrive at a branded error page belonging to redirect[.]pizza, a legitimate commercial link-forwarding service, reading "402 - Unable to redirect".
That single detail reframes the message. The domain in the email was never a phishing site. It was a front pointed at a hosted redirect service, with the destination held server side and resolved at click time. Where a victim ends up is written down nowhere in the email and is not discoverable from the domain's DNS records. The operator can change it, gate it by geography or user agent, or switch it off, and every message already sitting in an inbox keeps working as intended. MITRE tracks the pattern as spearphishing link paired with user execution of a malicious link, with a commercial service rented in the middle to hold the part of the attack that would otherwise be evidence.
Because the forwarding rule was already dead when the link was pulled, there is no verified account of what the final page looked like or asked for. Describing it would be invention, and the ambiguity is the point. Malicious link and payload inspection is only as good as what the link is willing to show a scanner.
The cloak was broken, and that is why it scanned quietly
A defender's instinct is to treat a dead link as good news. In practice, a broken cloak beats a working one. A live credential-harvest page renders, gets captured, gets classified, gets blocked, and the domain burns for everyone. A service error page produces no screenshot worth scoring, no form to fingerprint, and no brand to match, so the verdict lands between inconclusive and clean. The link here scored as a mixed result rather than a confirmed malicious hit, and that is the mechanical reason why.
Nothing about the email changes when the redirect breaks. Repoint the forwarding rule and every delivered copy becomes live again without a second send.
See Your Risk: Calculate how many threats your SEG is missing
A six-day-old domain wearing borrowed nameservers
WHOIS on the redirector domain showed a creation date six days before the message was sent, registered through a budget reseller, with DNS handed straight to Microsoft's managed nameservers. Those are the shared set Microsoft assigns to any customer domain it manages DNS for, so they are worthless as an indicator and slightly worse as a reassurance: a reputation check that glances at delegation rather than registration age sees Microsoft infrastructure and relaxes.
Six days is the loudest number in this case, and it was attached to the one asset nobody was scoring. Reputation systems were looking at the sending domain, registered back in 2010 with well over a decade of clean sending history. Domain age was measured on the wrong domain. MITRE files the underlying move as compromising existing email accounts rather than standing up new infrastructure, because the aged, reputable half of the operation is cheaper to borrow than to build.
Two mismatches sitting in the subject line
Two smaller observations were available for free to any human reader. The visible subject was a generic transaction notification rather than the legal matter the quoted correspondence below it concerned. And the reply prefix on it was not the English "RE:" but a localized equivalent produced by mail clients configured in another language, above a thread conducted entirely in English by two US law firms. The record establishes the mismatch, not how it came about, and neither proves attribution or replaces a header check. Both are simply what a recipient notices in the second or third second, if the message gives them a reason to look.
When the payload is a picture, the signal is the relationship
Authentication was flawless. SPF passed, DKIM passed on the firm's own tenant signing domain, DMARC passed with an aligned header, and ARC passed across the chain. All of it was true: the mail really did originate from a genuine, long-established practice's mail flow. Somebody was operating inside that mailbox, which is account takeover rather than impersonation, and the firm is a bystander rather than an actor. That is the context, and it is the least interesting thing in the case.
The signal that held up was relational. Despite the authentic thread beneath the image, this sender had never corresponded with this mailbox before, and the message carried a first-time-sender banner. First-time sender plus a payload consisting solely of an image plus a link to a domain registered days ago is a composite that no individual reputation check produces. That is the kind of correlation our Adaptive AI is built to make, and in this case both affected mailboxes were quarantined and later confirmed as mitigated after human review. No single confidence figure was recorded against this message; link and image risk signals carried it, together with the absent sending relationship.
Both CISA's phishing guidance and the definition NIST keeps for phishing frame the problem as deception rather than payload, the right frame for a message whose hostile content was entirely a rendered graphic. The 2024 DBIR puts the human element in 68 percent of breaches. There was nothing here for a signature to match.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Domain | capitolccmpm[.]com | Attacker-registered redirector, created six days before send through a budget reseller, DNS delegated to Microsoft's shared managed nameservers |
| URL | hxxp://capitolccmpm[.]com/ | The sole link in the message, wrapped around the embedded "Download completed documents" image |
| Service | redirect[.]pizza | Context only, NOT an indicator to block. A legitimate commercial link-forwarding service with many ordinary customers, rented here as a front; served its own "402 - Unable to redirect" page at scan time |
| File | image.png | Embedded lure graphic, 157,465 bytes, 764 by 451 pixels, md5 34c1f7446284a4ec760001d729f907b5, no macros or executable content |
| Redacted compromised law-firm mailbox | Genuine fully authenticated sender on an apex domain registered in 2010; abused bystander, not the attacker | |
| Behavior | Localized reply prefix on a generic transaction subject | Subject line did not match the quoted legal correspondence beneath it |
| Behavior | First-time sender carrying an authentic quoted thread | No prior correspondence history between this sender and this mailbox |
MITRE ATT&CK mapping
| Technique | ID | Where it appears |
|---|---|---|
| Phishing: Spearphishing Link | T1566.002 | A single link wrapped around an embedded image, resolving to a rented redirector |
| Compromise Accounts: Email Accounts | T1586.002 | Delivery from inside a genuine, long-established law firm mailbox with full authentication |
| User Execution: Malicious Link | T1204.001 | Requires the recipient to click the image; nothing executes on delivery |
What to take from this one
Score the newest asset in the message, not the oldest. The sending domain had fourteen years of history and perfect authentication, and both facts were accurate and irrelevant. The domain that mattered was six days old, hosted nothing, and existed only to hand the click onward. When the payload is a picture and the destination is rented, the durable question is one no scanner answers alone: has this sender ever written to this mailbox before?
Related attacks
| Attack | What happened |
|---|---|
| Authenticated From a Real Law Firm's Mailbox: A Fabricated Litigation Thread and a PIN-Gated OneDrive Credential Harvest | The message came from a real law firm's own domain, registered in 2012, with authentication that passed Microsoft's mail flow checks. |
| A Security Vendor's URL Defense Became the Attacker's Best Disguise | Attackers hijacked a real supplier email thread and weaponized Proofpoint URL Defense to wrap five malicious links in trusted redirect tokens. |
| The Signature Block Was Real. One Link in It Was Not. | A reply arrived inside a real weeks-old thread, from a real vendor mailbox, with a clean spreadsheet attached and every authentication check passing. |
| The DocuSign Button That Pointed at Adobe, and Redirected to an S3 Credential Page | A DocuSign-styled signature request arrived from a compromised European Microsoft 365 mailbox. |
| Compromised University M365 Account Delivers Thread-Hijacked Email With Malicious QR Shortlink and Suspicious Image Payloads | Attackers abused a compromised Singapore university M365 account to send thread-hijacked emails bearing a malicious QR shortlink and image attachments... |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.