Table of Contents
Three mailboxes at a multinational metals and mining group received the same attack within three hours and thirty seven minutes on 11 December 2025. Each one received a different code.
Arrivals at 09:26, 11:54, and 13:04 UTC. Three strings in the format XXXX-XXXXXX-XXXX, no two alike: 4YV5-UMJW8S-EDI8, 9GT7-UCWO0U-NUY0, 8OH0-UUQJ6M-QDM2. Three subject templates to match, one carrying a duplicated "Please Review" fragment that betrays a template concatenation bug.
Pick one and you can trace the entire attack by following it. In the third message the string 8OH0-UUQJ6M-QDM2 appears in five separate places. That is the finding here. Not a clever payload, but a production line stamping a serial number onto every component of one individual's attack.
The email had nothing in it
The IRONSCALES analysis pulled the full message body. It contains the recipient gateway's own external-sender caution banner, then ten line breaks. No attacker text. No images. No links at all: the incident's link array is empty.
The whole attack was an attachment, and it had no filename. The record shows it as literally .pdf, 93,265 bytes, md5 9e54ab16eb590d6583f265d30bfe383b. Verdict: Clean, and correctly so. Nothing executable, nothing embedded, nothing to detonate. This file is a link in a wrapper.
Decoded through the document's own ToUnicode maps, the PDF reads: "A secure document has been shared with you. Access it using the button below." Beneath that sits the delivery date, the victim organisation's own company name as the branding, and a button labelled "Review Documents." A second line offers to show the reader how to log in and e-sign. Two link annotations, both pointing at the same single URI action.
The code appears five times
Here is where that one string turns up in a single message:
- Prefixed to the visible sender display name, ahead of a portal lure.
- Bracketed into the subject line alongside the delivery date.
- As the first subdomain label on the landing host.
- As the second subdomain label, separated from the first by the digits
68142, which are uncharacterised. - As the key of the destination URL's fragment, where the value is the recipient's own mailbox, base64-encoded.
That last one carries the most weight. A URL fragment is never transmitted to the server. Anything after the hash is visible only to script in the browser, so the reasonable expectation is that the landing page reads the value client-side to pre-fill a credential form with the victim's address. Expectation, not observation. Because the URL lived inside the PDF, the link scanner never saw it and no page was ever captured, so what that host served is unobserved.
The display name also spells its portal lure with Cyrillic and Latin lookalike characters, the least interesting thing in this case.
The only clickable object was an unsubscribe link
Read directly out of the PDF's URI action, redacted and defanged:
hxxps://[MARKETING-PLATFORM][.]com/api/channels/email/unsubscribe?app_key=[REDACTED]&channel_id=[REDACTED]&push_id=[REDACTED]&message_type=commercial&campaigns=SME_First_Anniversary_Email_13092023&campaigns=MC&redirect=hxxps%3A%2F%2F[CODE]68142[CODE][.][LANDING-HOST][.]com[.]br%2FOFF-process%2Findex[.]php&sa=D&sntz=1&usg=[REDACTED]#[CODE]=[BASE64-VICTIM-MAILBOX]
Hop one is a real email marketing platform's unsubscribe API endpoint. Genuine path, genuine app_key, channel_id and push_id parameters, message_type=commercial. Plus a redirect= parameter the attacker controls. The platform is an abused bystander; its opt-out machinery became an open redirect.
Consider what that does to a secure email gateway (SEG), which scores reputation and content. The first domain it resolves belongs to a legitimate marketing vendor behaving exactly like one, on a path whose purpose is sending recipients elsewhere. The destination is buried in a percent-encoded parameter, and the whole string sits inside an attachment rather than the body. Reputation, sender authentication, and URL inspection each return a defensible answer, and the attack still lands. That is the case for credential harvesting defence that reads intent from the message as a whole.
See Your Risk: Calculate how many threats your SEG is missing
Recycled from a real 2023 marketing send
The campaigns=SME_First_Anniversary_Email_13092023 parameter embeds a date: 13 September 2023. The push_id is a UUIDv1 whose embedded timestamp field is consistent with 2023 as well. Nobody types values like those by hand. The attacker copied a working unsubscribe URL out of a genuine marketing email sent two years earlier and changed one parameter.
A second piece of residue: the URL still carries &sa=D&sntz=1&usg=..., the signature parameter set Google's own link wrapper appends, even though nothing in this chain routes through Google any more. Those parameters do nothing. They are lineage, left in place because removing them was never necessary, and exactly the sort of artifact worth hunting on.
Authentication passed, and it passed honestly
spf=pass, dkim=pass, dmarc=pass, compauth=pass reason=100. All four, genuinely, at the final hop. Microsoft scored the message SCL:1, SFV:NSPM, BCL:0 and delivered it to all three mailboxes.
Nothing was forged, because nothing needed to be. An authenticated client submitted the mail into a Japanese ISP's outbound message submission agent, meaning somebody was logged into a real mailbox at a real business. The submitting client IP is unrelated to that relay infrastructure, and how the account became usable is not determinable from this record. The mailbox owner is a victim of account abuse, not the attacker.
This is the practical limit of SPF and its companions. They answer whether a domain authorised a send, not whether the content is an attack. MITRE tracks this delivery pattern as T1566.001, spearphishing attachment, and the 2026 Verizon Data Breach Investigations Report puts phishing at 16% of breaches used for initial access, credentials at 39% across the full kill chain, and the human element at 62%, up from 60%.
Indicators worth keeping
Every domain in this chain belongs to a bystander, so the durable indicators are structural.
| Type | Indicator | Context |
|---|---|---|
| Pattern | XXXX-XXXXXX-XXXX per-recipient code | Prefixed to display name, bracketed in subject, doubled as subdomain label, used as fragment key |
| Code | 8OH0-UUQJ6M-QDM2, 9GT7-UCWO0U-NUY0, 4YV5-UMJW8S-EDI8 | Three codes, three mailboxes, one tenant, 3h37m |
| File hash | 9e54ab16eb590d6583f265d30bfe383b | PDF link carrier, 93,265 bytes, verdict Clean |
| Filename | .pdf with no stem | Zero-length attachment name |
| URL path | /api/channels/email/unsubscribe | Marketing platform opt-out endpoint abused as an open redirect |
| URL parameter | campaigns=SME_First_Anniversary_Email_13092023 | Recycled from a genuine 2023 marketing send |
| URL parameter | &sa=D&sntz=1&usg=... | Vestigial Google wrapper parameters, non-functional |
| URL path | /OFF-process/index[.]php | Final landing path on the redirect target |
| Subject artifact | Duplicated "Please Review" fragment | Template concatenation bug |
| IP | 103[.]125[.]216[.]235 | Submitting client IP at the message submission agent hop |
What actually stopped it
Human review. The incident state reads "Approved Manually," and every affected mailbox shows action Quarantined, status "Email was Mitigated or Reverted," mitigation timestamp 2025-12-11T20:07:23Z, plus an analyst comment. Three messages that Microsoft scored benign, that authenticated cleanly, and whose attachment was legitimately Clean, all pulled back the same day.
Advanced URL and malware analysis has to reach inside attachments rather than trust a body with no links in it, and treat a redirect parameter on a reputable host as a destination rather than a domain. Then the human layer has to be quick, because an empty body and a Clean attachment are not anomalies in that pipeline. They are the design.
Three changes worth making this week. Extract and follow URLs from inside attachments, including PDFs with no script: the link never appears where a body scanner looks. Flag reputable-host URLs carrying redirect parameters that point off-platform, a control CISA's phishing guidance has pushed for years and that the Microsoft Digital Defense Report 2024 frames as a core identity-attack vector. And hunt per-recipient tokens across sender, subject, and URL: a string repeated in all three is a personalisation tell no reputation feed will carry.
This attack handed the gateway a clean reputation and no content. IRONSCALES platform data puts the baseline at 67.5 phishing emails per 100 mailboxes each month, and the FBI IC3 2024 report counts phishing as the most-reported crime type by complaint volume. The NIST definition of phishing has barely changed in twenty years. The assembly line behind it has.
Related attacks
| Attack | What happened |
|---|---|
| DocuSign Phish Weaponizes Google Maps as a Redirect Proxy to Amazon S3 | A DocuSign-branded phishing email used Google Maps Belgium as a redirect proxy to route victims to a credential harvesting page hosted on Amazon S3. |
| Insurance Claim PDF Hides JavaScript Behind AcroForm Fields and SendGrid Redirects | A polished insurance claim notification delivers a PDF with interactive AcroForm fields and obfuscated JavaScript auto-execute tokens. |
| The PDF Scanner Couldn't Open the Attachment (But the Victim Could) | A password-protected PDF bypassed every automated scanner because none of them could open it. |
| The Zoho Invoice That Was Four Months Late (And Kept Its Receipts on Google Drive) | A Zoho Books invoice for $802.50 arrived four months past due, passed initial authentication checks. |
| The PDF Passed Every Scanner. Then It Opened a Browser Tab. | A 46KB PDF arrived clean on every attachment scanner. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.