TL;DR A recreational-marine manufacturer received a fake Adobe Acrobat Sign request that hotlinked real Adobe-hosted images for cover. The Open Document button led to a credential form hosted on the legitimate no-code automation platform n8n.cloud, on a user-controlled subdomain whose only tell was a misspelled word. SPF passed through a borrowed Japanese nonprofit relay, but DKIM was absent and DMARC was only a best-guess pass. Four mailboxes were hit and mitigated. Legitimate automation platforms are becoming a phishing-hosting layer that defeats simple domain-reputation checks.
Severity: High Credential Harvesting Brand Impersonation Trusted Infrastructure Abuse MITRE: T1566 MITRE: T1566.002

An employee at a recreational-marine manufacturer opened what looked like a routine document request. The message carried Adobe Acrobat Sign branding, the logos and layout rendered cleanly, and the images were served straight from Adobe's own document infrastructure. Everything above the fold said this was a legitimate eSignature notification. The single button that mattered, the one labeled Open Document, is where the story turns. It did not lead to Adobe. It led to a credential-collection form running on a legitimate no-code automation platform, and the only thing separating that form from ordinary business software was one misspelled word.

When the Brand Assets Are Genuine but the Destination Is Not

Brand impersonation usually leans on copied logos and near-miss lookalike domains. This campaign was more disciplined. The attacker hotlinked genuine Adobe-hosted images directly from Adobe's document domain, so the visual layer was not a copy at all. It was the real thing, pulled live from a trusted source. Any inspection of the images themselves would have found nothing wrong, because there was nothing wrong with them.

The deception lived entirely in the destination of the call-to-action. The Open Document button pointed to a user-controlled subdomain on n8n.cloud, the hosting service for a widely used no-code workflow automation platform. On that subdomain sat a webhook rigged to present a login prompt. The page did not hide its intent once you arrived. It plainly instructed the reader to "Authenticate viewing access with your user credentials," which is a request no legitimate eSignature workflow would ever make in that form.

The subdomain read as wirelesscommunicaton[.]app[.]n8n[.]cloud. Read it quickly and it looks like an internal communications tool. Read it slowly and the word "communication" is missing its second letter i. That misspelling was the entire visible tell. There was no lookalike top-level domain, no freshly registered host with a bad reputation, and no obvious redirect chain. The malicious form lived on the same trusted platform that thousands of businesses use for legitimate automation.

Why Trusted Infrastructure Is the Point

Attackers are increasingly staging credential harvesting on legitimate software-as-a-service (SaaS) platforms precisely because reputation-based defenses were never designed to distinguish a good tenant from a bad one on the same host. A domain-reputation check on n8n.cloud returns a clean, established service. An allow-list built around known-good business tools waves it through. The malicious content is not the domain, it is one customer's workflow running on that domain.

This is the same logic behind abuse of file-sharing links, form builders, and marketing-email platforms, extended to the no-code automation category. The Microsoft Digital Defense Report 2024 describes attackers steadily shifting toward trusted cloud services to launder both delivery and hosting, because those services carry reputation that raw attacker infrastructure cannot buy (Microsoft). The 2024 Verizon Data Breach Investigations Report puts stolen credentials at the center of intrusions, involved in 38 percent of breaches, with the human element present in 68 percent of them (Verizon). A form that harvests corporate logins from a trusted host feeds directly into both figures.

The Authentication Story Was Weaker Than It Looked

The message did not arrive from an Adobe address or from the impersonated department. The From display name spoofed a fabricated human resources and payroll group, while the envelope sender was an unrelated but legitimate Japanese nonprofit domain, relayed through a Japanese mail service.

It is tempting to call the authentication result a pass, but the detail matters. Sender Policy Framework (SPF) passed only because the borrowed nonprofit domain permits the relaying Internet Protocol address. DomainKeys Identified Mail (DKIM) was absent entirely. The Domain-based Message Authentication, Reporting and Conformance (DMARC) verdict was a best-guess pass, which is an inference drawn in the absence of a published, aligned policy, not a genuine aligned pass. The Spam Confidence Level (SCL) landed at 1. In short, one borrowed signal carried a message that had no real cryptographic alignment to any brand it invoked. That is exactly the kind of mixed, half-authenticated result that slips past filters tuned to treat any SPF pass as reassurance.

Mapping to MITRE ATT&CK

The campaign maps cleanly to two techniques in the MITRE ATT&CK framework. The overall approach is Phishing (T1566). The specific delivery mechanism, a message whose payload is a link to an attacker-controlled credential page rather than an attachment, is Spearphishing Link (T1566.002). The FBI Internet Crime Complaint Center 2023 report continues to rank phishing as the most-reported crime type by volume, which tracks with how routine and repeatable this pattern has become (FBI IC3).

Indicators of Compromise

IndicatorTypeNotes
wirelesscommunicaton[.]app[.]n8n[.]cloud/webhook/2900de16-3266-4f64-95b2-831dfd17e9bcCredential-harvest URLUser-controlled subdomain on a legitimate no-code automation platform; misspelled "communication" is the tell
A legitimate Japanese nonprofit domainBorrowed relayEnvelope sender abused to obtain an SPF pass; genuine third-party domain, not attacker-owned
Fabricated HR and payroll groupDisplay-name spoofFrom display name only; no alignment to any real sender

What Actually Catches This

Static rules struggle here because every ingredient except the misspelling is legitimate: real Adobe images, a real automation platform, a real relaying domain. Detection has to reason about the whole message. Adaptive AI weighs the mismatch between a payroll-branded display name and an unrelated envelope sender, the absence of DKIM against a brand that always signs, and a call-to-action that leaves trusted eSignature infrastructure for a webhook that asks for a login. Themis, the Adaptive AI analyst built into the IRONSCALES platform, scores those signals together rather than clearing a message the moment one reputation check comes back clean. That behavioral read is what separates a genuine notification from a genuine-looking one.

The takeaway for defenders is that domain reputation is no longer a reliable proxy for safety. When the credential form can live on the same trusted platform your own teams automate with, the question is not whether the host is known-good. It is whether the specific request makes sense. A payroll group does not route eSignature approvals through a misspelled automation subdomain, and no real login prompt asks you to authenticate your viewing access.

See your organization's real exposure to lures like this one with a look at credential harvesting protection.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Fireflies Meeting Recap That Never Happened: Dual-Brand Impersonation via Amazon SESA phishing campaign combined Fireflies.ai meeting recap templates with Microsoft Teams branding to target a financial controller.
The Law Firm Name That Used Invisible Characters to Pass AuthenticationA phishing email impersonating Alston & Bird LLP used homoglyph characters in the display name and rode Google Drive sharing infrastructure to pass SPF.
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
When 'Release from Quarantine' Is the AttackA fake quarantine digest weaponized email security workflows, embedding JWT tokens in 'Allow' and 'Manage' buttons while masking one link's true...
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.