TL;DR A phishing run against a multinational metals and mining group stamped a unique per-recipient code on every part of each victim's attack. In one message the same code appeared five times: in the sender display name, in the subject, twice as a subdomain label on the landing host, and as the fragment key whose value was the recipient's own mailbox in base64. The email body was empty. The whole attack was an untitled PDF whose single button abused a real marketing platform's unsubscribe endpoint as an open redirect, recycled from a genuine 2023 send.
Severity: High Credential Harvesting Malicious Attachment Open Redirect Abuse MITRE: T1566.001

Three mailboxes at a multinational metals and mining group received the same attack within three hours and thirty seven minutes on 11 December 2025. Each one received a different code.

Arrivals at 09:26, 11:54, and 13:04 UTC. Three strings in the format XXXX-XXXXXX-XXXX, no two alike: 4YV5-UMJW8S-EDI8, 9GT7-UCWO0U-NUY0, 8OH0-UUQJ6M-QDM2. Three subject templates to match, one carrying a duplicated "Please Review" fragment that betrays a template concatenation bug.

Pick one and you can trace the entire attack by following it. In the third message the string 8OH0-UUQJ6M-QDM2 appears in five separate places. That is the finding here. Not a clever payload, but a production line stamping a serial number onto every component of one individual's attack.

The email had nothing in it

The IRONSCALES analysis pulled the full message body. It contains the recipient gateway's own external-sender caution banner, then ten line breaks. No attacker text. No images. No links at all: the incident's link array is empty.

The whole attack was an attachment, and it had no filename. The record shows it as literally .pdf, 93,265 bytes, md5 9e54ab16eb590d6583f265d30bfe383b. Verdict: Clean, and correctly so. Nothing executable, nothing embedded, nothing to detonate. This file is a link in a wrapper.

Decoded through the document's own ToUnicode maps, the PDF reads: "A secure document has been shared with you. Access it using the button below." Beneath that sits the delivery date, the victim organisation's own company name as the branding, and a button labelled "Review Documents." A second line offers to show the reader how to log in and e-sign. Two link annotations, both pointing at the same single URI action.

The code appears five times

Here is where that one string turns up in a single message:

  1. Prefixed to the visible sender display name, ahead of a portal lure.
  2. Bracketed into the subject line alongside the delivery date.
  3. As the first subdomain label on the landing host.
  4. As the second subdomain label, separated from the first by the digits 68142, which are uncharacterised.
  5. As the key of the destination URL's fragment, where the value is the recipient's own mailbox, base64-encoded.

That last one carries the most weight. A URL fragment is never transmitted to the server. Anything after the hash is visible only to script in the browser, so the reasonable expectation is that the landing page reads the value client-side to pre-fill a credential form with the victim's address. Expectation, not observation. Because the URL lived inside the PDF, the link scanner never saw it and no page was ever captured, so what that host served is unobserved.

The display name also spells its portal lure with Cyrillic and Latin lookalike characters, the least interesting thing in this case.

The only clickable object was an unsubscribe link

Read directly out of the PDF's URI action, redacted and defanged:

hxxps://[MARKETING-PLATFORM][.]com/api/channels/email/unsubscribe?app_key=[REDACTED]&channel_id=[REDACTED]&push_id=[REDACTED]&message_type=commercial&campaigns=SME_First_Anniversary_Email_13092023&campaigns=MC&redirect=hxxps%3A%2F%2F[CODE]68142[CODE][.][LANDING-HOST][.]com[.]br%2FOFF-process%2Findex[.]php&sa=D&sntz=1&usg=[REDACTED]#[CODE]=[BASE64-VICTIM-MAILBOX]

Hop one is a real email marketing platform's unsubscribe API endpoint. Genuine path, genuine app_key, channel_id and push_id parameters, message_type=commercial. Plus a redirect= parameter the attacker controls. The platform is an abused bystander; its opt-out machinery became an open redirect.

Consider what that does to a secure email gateway (SEG), which scores reputation and content. The first domain it resolves belongs to a legitimate marketing vendor behaving exactly like one, on a path whose purpose is sending recipients elsewhere. The destination is buried in a percent-encoded parameter, and the whole string sits inside an attachment rather than the body. Reputation, sender authentication, and URL inspection each return a defensible answer, and the attack still lands. That is the case for credential harvesting defence that reads intent from the message as a whole.

See Your Risk: Calculate how many threats your SEG is missing

Recycled from a real 2023 marketing send

The campaigns=SME_First_Anniversary_Email_13092023 parameter embeds a date: 13 September 2023. The push_id is a UUIDv1 whose embedded timestamp field is consistent with 2023 as well. Nobody types values like those by hand. The attacker copied a working unsubscribe URL out of a genuine marketing email sent two years earlier and changed one parameter.

A second piece of residue: the URL still carries &sa=D&sntz=1&usg=..., the signature parameter set Google's own link wrapper appends, even though nothing in this chain routes through Google any more. Those parameters do nothing. They are lineage, left in place because removing them was never necessary, and exactly the sort of artifact worth hunting on.

Authentication passed, and it passed honestly

spf=pass, dkim=pass, dmarc=pass, compauth=pass reason=100. All four, genuinely, at the final hop. Microsoft scored the message SCL:1, SFV:NSPM, BCL:0 and delivered it to all three mailboxes.

Nothing was forged, because nothing needed to be. An authenticated client submitted the mail into a Japanese ISP's outbound message submission agent, meaning somebody was logged into a real mailbox at a real business. The submitting client IP is unrelated to that relay infrastructure, and how the account became usable is not determinable from this record. The mailbox owner is a victim of account abuse, not the attacker.

This is the practical limit of SPF and its companions. They answer whether a domain authorised a send, not whether the content is an attack. MITRE tracks this delivery pattern as T1566.001, spearphishing attachment, and the 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches used for initial access, credentials at 39% across the full kill chain, and the human element at 62%, up from 60%.

Indicators worth keeping

Every domain in this chain belongs to a bystander, so the durable indicators are structural.

TypeIndicatorContext
PatternXXXX-XXXXXX-XXXX per-recipient codePrefixed to display name, bracketed in subject, doubled as subdomain label, used as fragment key
Code8OH0-UUQJ6M-QDM2, 9GT7-UCWO0U-NUY0, 4YV5-UMJW8S-EDI8Three codes, three mailboxes, one tenant, 3h37m
File hash9e54ab16eb590d6583f265d30bfe383bPDF link carrier, 93,265 bytes, verdict Clean
Filename.pdf with no stemZero-length attachment name
URL path/api/channels/email/unsubscribeMarketing platform opt-out endpoint abused as an open redirect
URL parametercampaigns=SME_First_Anniversary_Email_13092023Recycled from a genuine 2023 marketing send
URL parameter&sa=D&sntz=1&usg=...Vestigial Google wrapper parameters, non-functional
URL path/OFF-process/index[.]phpFinal landing path on the redirect target
Subject artifactDuplicated "Please Review" fragmentTemplate concatenation bug
IP103[.]125[.]216[.]235Submitting client IP at the message submission agent hop

What actually stopped it

Human review. The incident state reads "Approved Manually," and every affected mailbox shows action Quarantined, status "Email was Mitigated or Reverted," mitigation timestamp 2025-12-11T20:07:23Z, plus an analyst comment. Three messages that Microsoft scored benign, that authenticated cleanly, and whose attachment was legitimately Clean, all pulled back the same day.

Advanced URL and malware analysis has to reach inside attachments rather than trust a body with no links in it, and treat a redirect parameter on a reputable host as a destination rather than a domain. Then the human layer has to be quick, because an empty body and a Clean attachment are not anomalies in that pipeline. They are the design.

Three changes worth making this week. Extract and follow URLs from inside attachments, including PDFs with no script: the link never appears where a body scanner looks. Flag reputable-host URLs carrying redirect parameters that point off-platform, a control CISA's phishing guidance has pushed for years and that the Microsoft Digital Defense Report 2024 frames as a core identity-attack vector. And hunt per-recipient tokens across sender, subject, and URL: a string repeated in all three is a personalisation tell no reputation feed will carry.

This attack handed the gateway a clean reputation and no content. IRONSCALES platform data puts the baseline at 67.5 phishing emails per 100 mailboxes each month, and the FBI IC3 2024 report counts phishing as the most-reported crime type by complaint volume. The NIST definition of phishing has barely changed in twenty years. The assembly line behind it has.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
DocuSign Phish Weaponizes Google Maps as a Redirect Proxy to Amazon S3A DocuSign-branded phishing email used Google Maps Belgium as a redirect proxy to route victims to a credential harvesting page hosted on Amazon S3.
Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid RedirectsA polished insurance claim notification delivers a PDF with interactive AcroForm fields and obfuscated JavaScript auto-execute tokens.
The PDF Scanner Couldn't Open the Attachment (But the Victim Could)A password-protected PDF bypassed every automated scanner because none of them could open it.
The Zoho Invoice That Was Four Months Late (And Kept Its Receipts on Google Drive)A Zoho Books invoice for $802.50 arrived four months past due, passed initial authentication checks.
The PDF Passed Every Scanner. Then It Opened a Browser Tab.A 46KB PDF arrived clean on every attachment scanner.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.