Table of Contents
Every authentication check on this email came back green. SPF passed. DKIM passed. DMARC passed. The From header read QuickBooks Support. And none of it meant what a reader would assume.
The sending domain, aceaccountings[.]com, was registered on September 6, 2023 and has no relationship to Intuit or QuickBooks of any kind. Reputation scans flagged it as a low-trust marketing domain. It authenticated itself perfectly, which is the entire trick. The message cleared the full SPF, DKIM, and DMARC gauntlet not by forging Intuit, but by proving its own identity while wearing a display name that pointed somewhere else.
There was no attachment. There was no credential-harvesting page. The email asked the reader to do exactly one thing: schedule a call.
A Clean Auth Record for a Domain That Is Not QuickBooks
The message was blasted through Mailercloud, a legitimate bulk-email platform, from the sending host mail.ov1002.mailecloud[.]com at IP 167[.]114[.]10[.]205. SPF passed on that address. DKIM signatures verified for both aceaccountings[.]com and the platform domain. DMARC passed with header.from=aceaccountings[.]com and an action of none.
That is a fully intact authentication chain, and it says nothing about the brand in the display name. Sender Policy Framework validates the server that sent the mail. DomainKeys Identified Mail validates that the body was not tampered with in transit. Neither one checks whether the domain has any authority to speak for QuickBooks. When the sending domain is unrelated to the brand being impersonated, a green DMARC verdict is authentication laundering: real cryptographic signatures wrapped around a lie about identity.
The lure leaned on manufactured urgency. Under a generic Dear QuickBooks User greeting sat a fabricated software discontinuation notice, a supposed end-of-life policy for QuickBooks Desktop that pressed the reader to act before a deadline. The body carried an embedded open-tracking pixel to confirm which recipients had viewed the message, then a single Schedule A Call Back button as the only meaningful call to action.
The Call Is the Payload
That button did not open a login page. It routed through a tracking link on the attacker-controlled subdomain mc.aceaccountings[.]com and landed on a Calendly booking page, calendly[.]com/specialist-advisors/book-qb-meeting. The reader was invited to book a slot with a QuickBooks specialist who does not exist.
This is the mechanic that makes the case worth studying. The email is not the attack. It is the doorway to the attack. The real social engineering waits on the phone call the victim schedules themselves, where a live operator walks them toward remote access, a payment, or a credential handover with no email artifact to inspect. Security teams know this pattern as telephone-oriented attack delivery, and it is a close cousin of vishing. Because the email contains no malicious link to a spoofed portal and no weaponized attachment, most signature and reputation engines have nothing to catch. The message was categorized as bulk mail and auto-quarantined to Junk, yet it kept returning across several mailboxes at a mid-size company over several days, each recipient another chance for one person to pick up the phone.
See Your Risk: Calculate how many threats your SEG is missing
The reason attackers keep reaching for the phone is simple economics of trust. The 2024 Verizon Data Breach Investigations Report puts the human element in 68 percent of breaches and names pretexting, most of it business email compromise, as the top social-engineering incident type, with a median transaction of roughly 50,000 dollars. The FBI's 2023 Internet Crime Report describes tech-support and call-center impersonation fraud among the costliest categories it tracks, which is precisely the endgame a QuickBooks-support callback is built to reach. The Microsoft Digital Defense Report 2024 documents the same broad shift toward abusing trusted services and legitimate infrastructure rather than breaking them.
Mapping to MITRE ATT&CK
The tradecraft lines up with a handful of techniques in the MITRE ATT&CK framework:
- T1566 Phishing and T1566.002 Spearphishing Link cover the delivery, a socially engineered message whose CTA routes through a tracking link to an external booking page.
- T1656 Impersonation covers the core deception, the QuickBooks Support display name standing in for a brand the sending domain has no connection to.
- T1598 Phishing for Information covers the open-tracking pixel and the callback funnel itself, both designed to identify and qualify a live human target before the phone conversation begins.
Indicators of Compromise
| Type | Indicator | Context |
|---|---|---|
| Domain | aceaccountings[.]com | Impersonation sender domain, registered Sep 6 2023, no Intuit or QuickBooks affiliation |
support@aceaccountings[.]com | From and Reply-To address used for the QuickBooks Support impersonation | |
| Domain | mail.ov1002.mailecloud[.]com | Mailercloud bulk-send infrastructure, sending IP 167[.]114[.]10[.]205 |
| URL | hxxps://mc.aceaccountings[.]com/links/[token]/3372594 | Schedule A Call Back tracking link on attacker-controlled subdomain |
| URL | hxxps://calendly[.]com/specialist-advisors/book-qb-meeting | Calendly booking page where the victim schedules the callback |
Detection and What to Watch For
Static gateways were always going to struggle here. The infrastructure is legitimate, the authentication is clean, and there is no link to a fake portal and no attachment to detonate. Detection has to move to behavior and intent. The signals that matter are a mainstream brand in the display name paired with a From domain that has no tie to it, a young sending domain riding a bulk marketing platform, an open-tracking pixel on a message that claims to be a support notice, and a call to action whose only destination is a scheduling page rather than the brand's real site.
This is where our Adaptive AI adds a layer that reputation checks miss. Themis, the analyst engine on the IRONSCALES platform, reads the relationship between the claimed brand, the actual sending domain, and the off-platform booking funnel the way a trained analyst would, and flags the impersonation even when every server-level check comes back green. That perspective is drawn from 36,000+ security professionals across 18,000+ organizations, the kind of cross-tenant visibility a single mailbox cannot see. CISA's guidance on stopping phishing at the recognition stage is a solid reference for building that reflex across a team: https://www.cisa.gov/resources-tools/resources/phishing-guidance-stopping-attack-cycle-phase-one
The Takeaway
A green DMARC pass is not a trust badge. It tells you a domain sent its own mail cleanly, nothing more, and an attacker who registers a throwaway domain can earn that pass in an afternoon. When the domain behind a familiar brand name is a stranger, and the only thing the message wants is for you to pick up the phone, the authentication result is the least interesting fact on the screen. Verify the sending domain against the brand it claims, treat unsolicited support deadlines as a pressure tactic, and confirm any account or software notice directly with the vendor before dialing a number an email handed you. Pairing that habit with behavioral detection is what closes the gap this campaign was built to exploit, and it is the same discipline that blunts business email compromise when the next impostor comes calling.
Related attacks
| Attack | What happened |
|---|---|
| McAfee Invoice Scam Weaponized a Google Calendar Invite 71 Minutes After Domain Registration | A same-day registered domain abused Google Calendar invites to deliver a McAfee/Webroot invoice scam with a callback phone number. |
| The Partner Invite That Used the Wrong Sending Domain | A calendar invite appeared to be from an IRONSCALES employee arranging an ANZ distribution call. |
| The Geek Squad Invoice With a Hidden Executable in the Image | A callback phishing attack delivered a fake Geek Squad invoice as an image with MZ/PE executable bytes embedded in the JPEG. |
| The Fake Invoice That Wasn't Even the Right File Type | A callback phishing attack used a PNG image disguised as a JPEG to deliver a fake Geek Squad invoice. |
| Salesforce Pardot Infrastructure Weaponized in Fabricated-Thread CRM Consulting Phish | A phishing campaign abused Salesforce Pardot and ExactTarget infrastructure to deliver a fabricated-thread CRM consulting lure with full SPF, DKIM. |
Explore More Articles
Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.