Table of Contents
Look at the display name and you would swear it said Indeed. It read lndeed. The capital I had been quietly replaced with a lowercase L, a swap most fonts render close enough to identical that the eye fills in the rest. The same trick sat inside the sending domain. And the whole thing arrived from a domain registered the same day it hit the inbox.
The targets were not random. The message landed in several HR and talent-acquisition mailboxes at a national bank, the exact people who live inside job-board and applicant-tracking tools all day. To them, an Indeed notice with an [ACTION REQUIRED] tag on the subject line is not an anomaly. It is Tuesday.
That is what makes this case worth a look. There was no malware, no attachment, no exotic exploit. The attacker spent almost nothing, borrowed a real company's mail platform, and leaned on one dropped letter and the right audience.
One Letter, Planted Twice
The sender was employers@lndeeclemali[.]com, presenting the display name lndeed. Both the visible name and the domain carried the same lowercase-L-for-capital-I homoglyph, so a recipient scanning quickly would map both to the real brand. The domain itself was registered the same day the campaign fired, behind privacy protection that hid the registrant. A brand-new lookalike domain with no history is a textbook setup for credential harvesting: there is nothing for a reputation service to have flagged yet, and no prior sending pattern to compare against.
The lure was deliberately generic. [EXTERNAL] [ACTION REQUIRED] Confirm Your Account is the kind of subject that works on anyone with an account somewhere, which is everyone. No name, no personalization, no reference to a specific job posting. The attacker was not trying to win a spearphishing chess match. They were trying to get one recruiter, on a busy morning, to click a confirm button that looked like it came from a tool they already trust.
Riding a Real Marketing Platform
The message did not originate from some sketchy bulletproof host. It was sent through Campaign Monitor, a legitimate email marketing platform, on its cmail19[.]com sending infrastructure, and relayed onward through a Mimecast gateway. Thousands of real newsletters ride those same rails every day, which is precisely why it works as cover. The reputation attached to a mainstream marketing platform gets a message a long way before anyone questions it.
The confirm button did not point straight at a destination either. It was wrapped in Mimecast Protect, the recipient's own link-protection layer, and resolved to a campaign-tracking page on godaddy.cmail19[.]com, a Campaign Monitor client subdomain. That page was styled to mimic Indeed's account-confirmation screen. So the victim's security tooling rewrote the link, the rewritten link still pointed at legitimate marketing infrastructure, and the landing page wore Indeed's clothes. Every hover-and-inspect habit a trained user might apply returned a reassuring answer.
See Your Risk: Calculate how many threats your SEG is missing
When Authentication Degrades Between Hops
The authentication trail on this one is the part worth slowing down for, because it looks like a pass and a fail at the same time. At the Mimecast relay hop, the message checked out: DKIM passed for the sending domains, SPF passed, and DMARC passed. That is what riding a real platform buys you. The platform is authorized to send, so its own signatures validate.
At final delivery to the recipient, all of that came apart. SPF landed on softfail, DKIM failed on a body-hash mismatch, and DMARC failed for the header From of lndeeclemali[.]com. The reason is structural: a same-day-registered lookalike domain cannot genuinely align to the platform's signing identity, so once the message is evaluated against the brand it claims to be, the alignment collapses.
The practical lesson is that authentication is only as strong as the hop that enforces it. A pass at a trusted relay can carry a message far enough that the final failing verdict arrives after a human has already read the subject line and reached for the button. Server-level checks describe the plumbing. They do not read intent.
Mapping to MITRE ATT&CK
The tradecraft maps cleanly onto the MITRE ATT&CK framework:
- T1583.001 Acquire Infrastructure: Domains covers the same-day-registered, privacy-protected homoglyph domain purchased specifically for this campaign.
- T1036.005 Masquerading: Match Legitimate Name or Location covers the lowercase-L homoglyph planted in both the display name and the domain to pass for Indeed.
- T1566.002 Spearphishing Link covers the account-confirmation link delivered through a marketing platform, and T1204.001 User Execution: Malicious Link covers the click the whole scheme depends on.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Domain | lndeeclemali[.]com | Same-day-registered, privacy-protected homoglyph domain impersonating Indeed |
employers@lndeeclemali[.]com | Sender address, display name lndeed with lowercase-L homoglyph | |
| Domain | cmail19[.]com | Legitimate Campaign Monitor sending infrastructure abused to deliver the campaign |
| URL | hxxps://godaddy.cmail19[.]com/t/y-l-abjrul-hklygjliu-r/ | Confirm Your Account tracking link, landing page styled to mimic Indeed |
| Subject | [EXTERNAL] [ACTION REQUIRED] Confirm Your Account | Generic urgency lure sent to multiple HR mailboxes |
Detection and What to Watch For
Signature and reputation checks were never going to catch this. The infrastructure is legitimate, the message carries no payload to scan, and the lookalike domain had no history to condemn it. Detection has to move to behavior and relationship: a first-contact sender claiming a household brand, a header From that visually approximates that brand but is not it, a domain with no age, and a confirm-your-account urgency pattern aimed at a job-function group.
That is the layer Themis, the Adaptive AI analyst on the IRONSCALES platform, is built to read. It weighs the claimed brand against the actual sending domain and the recipient's normal contact graph the way a trained analyst would, flagging the impersonation even when every server-level check at the relay came back green. The 2024 Verizon Data Breach Investigations Report ties stolen credentials to 38 percent of breaches, the single most common way in, and the Microsoft Digital Defense Report 2024 documents the same shift toward abusing trusted services rather than breaking them. The FBI's 2023 Internet Crime Report puts business-identity and brand impersonation among the costliest fraud categories, which is exactly the lever a recruiter-targeted Indeed lure pulls. Across the 35,000+ security professionals and 17,000+ organizations in the IRONSCALES community, homoglyph brand spoofs like this one are a recurring pattern, not an outlier.
The Takeaway
Homoglyph attacks win on speed and familiarity. A lowercase L costs nothing, a same-day domain costs a few dollars, and a real marketing platform supplies the reputation for free. The defense is to stop trusting display names as identity and to treat a green authentication verdict at one hop as a starting point, not a conclusion. Verify the brand against the domain, weigh the sender's history, and give behavioral detection the final say. The next dropped letter is already being registered.
CISA's guidance on recognizing and stopping phishing early is a solid reference for building that reflex across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one
Related attacks
| Attack | What happened |
|---|---|
| The DocuSign Lure That Used Google as a Trust Shield (And Encoded Your Email in the Link) | A DocuSign phishing email hid its harvest domain behind a google.com redirect and encoded the recipient's exact email address into the link as base64. |
| The Button Text Was the Weapon: Unicode RTL Obfuscation Inside a DocuSign Lure | Attackers embedded Unicode right-to-left marks directly inside a CTA button label to scatter the string for NLP scanners. |
| Instagram Homoglyph Phish Abuses Google Redirect API | One lowercase letter turned a routine Instagram notice into a credential trap. |
| Amazon SES Abuse Delivers Fake DocuPortal+ Notification to a Credential-Harvest Page With a Fake reCAPTCHA | Attackers routed a fake DocuPortal+ document-share notification through Amazon SES, giving it legitimate SPF and DKIM signatures. |
| MSC Brand Impersonation Abuses a Legitimate Open Redirector and Base64-Encodes the Victim's Address for Targeted Tracking | Attackers cloned Mediterranean Shipping Company branding, then funneled victims through a redirect endpoint on a legitimate third-party retail site to... |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.