Table of Contents
One query against a single tenant's own domain, run as if it were an external supplier's, returned ten auto-resolved malicious self-spoofs across eight of its own employees' mailboxes in three months. No single-sender block list would have touched one of them.
The message that surfaced it had no body. Not a short body, not a body hidden behind padding. get_email_body returned null, because there was nothing to return.
The top-level Content-Type was application/vnd.openxmlformats-officedocument.wordprocessingml.document, with Content-Disposition: attachment. The message was a Word document. No text/plain part, no text/html part, nothing for a content filter, a banner injector or a link extractor to read.
Inside that document sat two QR codes. Both decoded to the identical URL, and the final path segment of that URL was the recipient's full corporate email address in cleartext.
The Worked Example, Briefly
The recipient was an employee at a UK property consultancy running 1,339 mailboxes on M365. The message arrived 2026-05-20 as a self-addressed spoof: the From display name was the company's own brand, the From address was the employee's own mailbox, and the To and Return-Path matched it. The attachment was named salary increment_ID8b8bd3908c7492f6dddf.docx.
Authentication failed at the real sending hop, not as a forwarding artifact. SPF softfailed against sending IP 192.3.7.3, DKIM was none because the message was never signed, DMARC evaluated to fail with an oreject action recorded, and compauth returned none with reason 451. The message reached the mailbox regardless.
The sending host was a US commercial VPS. The Received line shows a client-supplied HELO of [127.0.0.1] arriving from a routable ColoCrossing address. Worth being precise: a genuine (localhost [127.0.0.1]) peer is same-machine plumbing, evidence against forgery. Here the loopback was the claimed name and a routable commercial host was the real peer.
Both QR images were extracted and decoded. The destination was a path on a real Brazilian website, opening with a directory named sharepointo, a SharePoint typosquat expressed as a path rather than a domain. Beneath it sat a second hardcoded directory whose name is the kit author's own crude shorthand, then the target's address. What that destination served was never captured. Both links have has_screenshot false, so nothing here characterises the page or the site.
Themis scored the message at confidence 90, labelled it a QR Code Attack, and returned two structural sender insights: sender address spoofing, and an external sender using an internal-looking address to mail itself a suspicious attachment, a pattern associated with Direct Send phishing. That read is automated. There is no human malicious verdict here.
Every automated verdict on the payload read clean. The attachment: clean. Both QR-derived links: clean. Reputation scoring on the apex of a real site tells you nothing about a kit three directories down. Structure caught this. Content and reputation did not, and a SEG (secure email gateway) is built on those two.
See Your Risk: Calculate how many threats your SEG is missing
Ask What Your Own Domain Has Been Doing in Your Own Inbox
Here is the query that changed the picture.
Security teams investigate external sender domains constantly. A supplier behaves oddly, you pull its sending history against your tenant and look at the shape. Almost nobody runs that query against their own domain, because a company's own namespace does not feel auditable.
Run it anyway. Against this tenant's own domain, a sender history scan since 2025-03-16 returned 15 untruncated incidents. Ten were automatically resolved as phishing, two were unresolved, and zero carried a human malicious verdict.
Those ten malicious self-spoofs did not share a spoofed identity. They rotated through eight distinct real employee mailboxes between 2026-05-20 and 2026-08-19, one of them recurring on three separate dates. A second self-addressed Direct Send message landed on the same day as the worked example above, wearing a different colleague's identity.
The pretexts stayed inside one family and never repeated verbatim: an additional benefits release, a payroll and compensation update, an annual salary increase, an employee handbook addendum, a password expiry notice. Several subjects carried per-send random reference tokens and hex-hash-style trailers, so subject-line matching across sends degrades badly.
Call this a sustained pattern and a campaign family, not one actor. The other nine incidents' headers, IPs and payloads were not pulled, so a shared tenant, mechanic and pretext family are the full extent of the linkage.
The operational point survives that caveat. The attacker was not impersonating the CEO, or business email compromise's favourite finance director, or a generic "HR Team" alias. It was enumerating the staff directory and wearing the workforce one name at a time. Every individual spoof is a first occurrence, and none of it aggregates until you group by claimed domain rather than claimed mailbox.
Delivery maps to T1566.001 for the attachment payload and T1566.002 for the QR-delivered link. The rotation defeats the control.
A Contested Internal Namespace
Two other things are true of the same tenant, as co-occurring facts rather than cause and effect. The same sender history holds three human False Positive verdicts on genuine internal service-account mail: a content-policy notification, an IT ticket assignment and a remittance advice. A further report on an internal timesheet notification was unresolved. In two, the end-user reason given was an impersonation attempt.
Those mailboxes are entirely different from the eight the campaign wore. The identity sets are disjoint, and there is no evidence the spoofing caused the service-account reports. What the pair establishes is an internal namespace contested in both directions: real self-spoofs land, and legitimate internal service mail gets reported as impersonation.
Why Authentication Was Not the Control
The 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches as an initial access vector and the human element at 62% of breaches overall, up from 60%. Microsoft's Digital Defense Report 2024 and CISA's phishing guidance both push authentication as the structural fix, rightly.
They are not sufficient alone. Authentication did its job here: DMARC evaluated to fail with an oreject action recorded, and the message was in the mailbox anyway. A recorded policy action is a recorded action, not a guaranteed outcome.
The detection that works is structural. From equals To equals Return-Path, arriving from an external host, is an anomaly regardless of the claimed sender. A message whose top-level MIME type is the attachment has no body to inspect, and that absence is a signal, not a gap. And QR extraction has to run inside attachments, because the URL had no body to live in.
Run the Inverted Query This Week
Across 36,000+ security professionals and 18,000+ organizations, IRONSCALES platform data shows self-addressed internal spoofs are routine rather than exotic. What is not routine is looking for them in aggregate.
Take your own domain and run it through whatever sender history view your platform gives you, exactly as you would a supplier you had begun to doubt. Group by claimed domain, then count distinct mailboxes.
If that count is larger than one, you are not looking at incidents. You are looking at a campaign, and Themis and the agent layer see the rotation long before a block list does, because it correlates on structure rather than the From field.
| Type | Indicator | Context |
|---|---|---|
| URL | hxxps://ludic[.]com[.]br/sharepointo/ | QR destination, both codes decoded identically. Graded clean. |
| File | salary increment_ID8b8bd3908c7492f6dddf.docx | Top-level MIME entity, 34,392 bytes, verdict clean |
| MD5 | 7b345c70139fddba7c1828108894d9e2 | Attachment hash |
| IP | 192.3.7.3 | Real sending peer, PTR 192-3-7-3-host.colocrossing.com |
| Header | HELO [127.0.0.1] | Client-supplied name from a routable commercial host |
| Pattern | From == To == Return-Path, external origin | Self-addressed Direct Send spoof |
Related attacks
| Attack | What happened |
|---|---|
| The Vendor Compliance Email Where Every Link Was Real and Every Authentication Check Passed | A vendor compliance onboarding email sent through Salesforce infrastructure passed SPF, DKIM, and DMARC with compauth 100. |
| The Zoho Invoice That Was Four Months Late (And Kept Its Receipts on Google Drive) | A Zoho Books invoice for $802.50 arrived four months past due, passed initial authentication checks. |
| Access Denied (To Scanners Only): A Presigned S3 Link | A phishing email routed a municipal HR employee to a payload hosted on a presigned AWS S3 URL. |
| The Button Text Was the Weapon: Unicode RTL Obfuscation Inside a DocuSign Lure | Attackers embedded Unicode right-to-left marks directly inside a CTA button label to scatter the string for NLP scanners. |
| The GitLab Alert That Passed Every Filter (Except One Detail Nobody Checked) | A GitLab sign-in alert cleared Proofpoint URL Defense and passed SPF/DMARC — then listed a private RFC1918 IP as the sign-in source. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.