TL;DR A fake annual-salary-review notice reached the finance team at a large India-based consumer-goods manufacturer, delivered from a real, DKIM-signed business domain that had almost certainly been compromised. The only call to action was a pair of QR codes, keeping the destination invisible to URL scanners. The giveaway was a templated phishing kit that forgot to localize itself: the subject line and HR footer named an unrelated company, and a reserved-for-fiction placeholder phone number sat in the footer. Authentication passed cleanly, yet both targeted mailboxes were quarantined on behavioral signals.
Severity: Medium Quishing Credential Harvesting Brand Impersonation MITRE: T1566 MITRE: T1204.001 MITRE: T1027

A payroll email arrived at the finance department of a large India-based consumer-goods manufacturer. It passed DKIM. It passed DMARC. It scored a perfect 100 on Microsoft's compound authentication. By every transport-layer measure, the message was clean.

It was also quarantined, because the fraud was never in the headers. It was in the subject line, which named the wrong company.

The lure was an "Annual Salary Review" notice, the kind of message a finance employee opens without a second thought in December. Two recipients were targeted, including a VP-level executive. But the phishing kit behind it had been reused across many victims, and its operator forgot the most basic step: swapping in the right target details for this batch. The result is a useful teardown of why authentication is not trust, and why the content of a message still betrays a kit that its transport never would.

The Kit That Forgot to Change the Address

The subject line and the "HR contact" footer both referenced a company that had nothing to do with the actual recipient's employer. The HR domain in the footer belonged to a completely different organization. To a finance clerk scanning fast, that reads as noise. To an analyst, it is a signature. A message purporting to be an internal salary review should reference the recipient's own company, not a stranger's.

The rest of the template carried the same fingerprints of mass reuse. A placeholder phone number, (555) 123-4567, sat in the footer unedited. That prefix is reserved for fiction, which is exactly why it survives in a kit that its operator never bothered to localize. Compensation fields that a real HR notice would populate were left generic. None of this is a transport artifact. It is the residue of a template built to be sent at scale and personalized never.

This is the class of attack that static filtering handles worst. There is no attacker-registered lookalike domain to blocklist, no malware attachment to detonate, and no misaligned SPF record to reject on. The malicious signal lives entirely in the mismatch between what the message claims and who received it.

QR Codes as the Only Door

The sole call to action was a pair of embedded QR codes, presented as the way to "access your detailed payslip." There was no clickable link anywhere in the body.

That design choice is deliberate. This technique, quishing, moves the click off the monitored corporate endpoint and onto a personal phone, where corporate controls rarely reach. It also hides the destination from text-based and URL-based scanners, which parse hyperlinks but do not decode image-embedded codes by default. A gateway can inspect an href all day and never see the URL painted inside a QR bitmap. The Microsoft Digital Defense Report 2024 documents attackers steadily shifting toward exactly this kind of evasion, leaning on trusted rails and non-standard payloads rather than brute-forcing their way past authentication.

Because no link was captured for inspection, the safe assumption from the salary-review pretext and the payslip lure is credential harvesting: a scanned code leading to a fake payroll portal that asks the employee to sign in.

Authentication Laundering Through a Compromised Domain

Here is the uncomfortable part. The message was sent from a real, decade-old business domain (registered in 2012) whose account or sending infrastructure had almost certainly been compromised. Because the mail was genuinely signed by that domain, DKIM passed, DMARC aligned under a policy of action=none, and compound authentication returned a perfect score.

The only wrinkle was a Sender Policy Framework (SPF) softfail, introduced when the message transited a legitimate Barracuda email-security gateway on its way out. A relay hop rewrote the path enough to soften SPF, but DKIM and DMARC carried the day regardless. Authentication answered the question it is designed to answer, "was this message really sent by this domain," and the answer was yes. What authentication cannot answer is whether that domain should be trusted at all when it has been quietly taken over.

This is the recurring lesson of compromised-sender abuse: a passing DMARC verdict certifies the envelope, not the intent behind it.

See Your Risk: Calculate how many threats your SEG is missing

Mapping to MITRE ATT&CK

The tradecraft maps to a few techniques in the MITRE ATT&CK framework:

  • T1566 Phishing covers the socially engineered salary-review lure delivered by email.
  • T1204.001 User Execution covers the action the attack depends on: a human scanning the QR code and completing the follow-on login.
  • T1027 Obfuscated Files or Information covers the QR encoding itself, which conceals the destination from automated inspection.

Indicators of Compromise

IndicatorTypeNotes
(555) 123-4567Placeholder phoneReserved-for-fiction number left unedited in the template footer, a tell of kit reuse
Two embedded QR codesCTA payloadSole call to action; no clickable link, hiding the destination from text and URL scanners
Subject and HR-footer domain mismatchTemplate artifactNamed an unrelated company rather than the recipient's employer
SPF softfail with DKIM pass and DMARC passAuth signatureCompound authentication scored 100 despite the relay-induced SPF softfail
Themis verdict: Invoice Phishing, 90% confidenceDetection outcomeBoth targeted mailboxes quarantined

What Actually Caught It

Signature and reputation checks were never going to stop this. The infrastructure was legitimate, the signing was valid, and there was no URL to score. Detection had to read intent. The signals that mattered were the salary-review pretext arriving from an external domain, the HR footer naming a company unrelated to the recipient, the placeholder phone number, and a QR-only call to action with no supporting link.

That is the layer static gateways miss and where our Adaptive AI earns its keep. Themis reads the relationship between the claimed context, the sending domain, and the payload the way a trained analyst would, flagging the mismatch at 90 percent confidence and quarantining both copies before anyone reached for a phone. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and stolen credentials in 38 percent, the top initial action; the FBI's 2023 Internet Crime Report similarly ranks business-identity and payment-themed fraud among its costliest categories. A payslip lure sits squarely in that blast radius. CISA's guidance on stopping phishing early is a solid reference for building the habit across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one

The Takeaway

Authentication tells you a domain sent a message. It does not tell you the domain is still in the right hands, and it says nothing about a payload it cannot see. When the call to action is a QR code, the destination has left the reach of every text-based control you own. Treat internal-looking payroll and HR notices as claims to verify, not facts to act on, and make sure your defenses can decode the parts of a message a scanner skips. See where quishing and payroll-themed fraud hide in your own mail flow with dedicated QR code attack protection, because the next kit will remember to change the subject line.

Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
A Pixel-Perfect Sephora Delivery Notice Shows Why Email Authentication Alone Can't Protect YouA fully authenticated Sephora delivery notification passed SPF, DKIM, and DMARC with perfect scores.
The QR Code That Knew Your Email Address Before You Scanned ItA phishing PDF embeds a QR code with the recipient's email pre-encoded in base64.
The Email That Passed Every Security Check (Because Adobe Sent It)A phishing campaign targeting school district staff used Adobe's own sending infrastructure, real DKIM signatures.
The Phishing Infrastructure Was Canva. The Delivery Mechanism Was Canva. The Authentication Was Canva.An attacker signed up for Canva, built a phishing lure as a design, and used the platform's own sharing feature to deliver it.

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.