TL;DR An e-signature completion notice reached an electronics distributor's administration function carrying no lure text a scanner could parse. The entire pretext, including the recipient's own address, was rasterized into two inline PNGs. The button wrapped the whole hero image in a recycled Google redirect whose target domain had been registered sixteen minutes before the message was sent. Below eight hundred pixels of blank spacer sat a genuine, stolen marketing opt-in confirmation from an unrelated business, so the only machine-readable text in the message belonged to somebody else.
Severity: High Credential Harvesting Brand Impersonation Evasion MITRE: T1566.002 MITRE: T1583.001 MITRE: T1204.001 MITRE: T1036.005

The button said "Review Document." Hovering it produced a link beginning hxxps://www[.]google[.]com/url?, Google's own link-rewriting endpoint and about as calming a prefix as a URL gets. The domain buried in that wrapper's q= parameter had come into existence sixteen minutes and seven seconds before the message was sent.

That was the attack, and almost none of it was written down. The e-signature completion notice that landed in an administration mailbox at an Israeli electronics distributor carried no lure text at all. Every word a person could read was a picture.

The Body Had Nothing to Read

In the HTML source, the hero block's heading and paragraph elements were literally empty. The only markup inside them was an anchor wrapping an inline image, followed by a second inline image: two PNGs, 33,867 and 27,368 bytes, both CID attachments, both scanned clean.

The first image was a purple panel with a pencil-in-a-circle glyph, the line "Your Document Has Been Completed," a note that all other parties had finished signing, and a call-to-action button. It named no vendor: no logo, no product name, nothing for a brand-impersonation detector to match, just a generic e-signature panel of the kind accounts payable sees weekly.

The second image did the personalization. It rendered the recipient's own mailbox address, an instruction to review the document by clicking above, and an invitation to contact the sender. That address, the element most likely to convince the reader the message was meant for them, existed only as pixels. Text extraction could not see it, and neither could data-loss prevention, which is built to notice addresses in text. This is masquerading as a routine notification with the masquerade moved outside the parser's reach.

The subject line added a fabricated document reference, a same-day signature deadline, and an eleven-character random suffix to defeat exact-subject clustering.

A Destination That Had Not Existed at Breakfast

WHOIS on the landing domain is the part of this case that needs no interpretation. The registration record was created, edited again roughly ten minutes later, and the message left the sending platform sixteen minutes and seven seconds after creation. The attacker was still adjusting the registration while the campaign was being loaded.

The record itself is junk. It was bought through a Hong Kong registrar, pointed at Cloudflare name servers, given a registrant country matching nothing else in the case, and its registrant state field holds a truncated fragment of Lorem ipsum filler. The term is one year, the minimum. DNSSEC is unsigned. Nobody intended this name to survive the week.

That is why reputation scoring could not help. Blocklists and domain-reputation services grade observed behavior, and a host with sixteen minutes of history has produced none to grade. It is not bad yet, it is not anything yet. Acquiring fresh infrastructure immediately before use is not sophisticated, just unanswerable for any control that waits for evidence.

The landing page was never rendered in the record, so what waited there is unknown. The URL carried a long per-recipient identifier token, the signature of a kit tracking which mailbox opened it.

The Link That Started With Google

The clickable region was the entire hero image, and the href was not a direct link to that new domain. It was hxxps://www[.]google[.]com/url?hl=en&q=hxxps://pristobiz[.]com/erndpreview?id=267e1d7d...506bfb&source=gmail&usg=AOvVaw0c6QuxwhsxiG5q5bUpHGpj.

The source=gmail and usg= parameters are the tell. This is not a hand-built redirect chain. It is a recycled link-rewrite wrapper, the kind Gmail generates automatically when it renders an outbound link, lifted intact and repointed. The attacker did not have to build redirector infrastructure or compromise a site to host one. They reused a wrapper a mail client had already produced, and inherited a URL whose first and most visible component is one of the most trusted apex domains on the internet.

See Your Risk: Calculate how many threats your SEG is missing

Every hover preview and every user trained to "check the link before you click" reads left to right and stops at www.google.com. The 2024 Verizon Data Breach Investigations Report puts the median time from opening a phishing email to clicking its link at 21 seconds. That is not enough time to parse a query string.

Eight Hundred Pixels of Nothing, Then Somebody Else's Mail

Below the two images sat two spacer divs, 500 pixels and 300 pixels tall, then a horizontal rule. Under that, the attacker had pasted a complete and entirely genuine marketing double-opt-in confirmation in French, belonging to an unrelated coaching business with no connection to the sender, the recipient, or the lure. Copy, working unsubscribe link, real postal address block, marketing-platform badge and a one-pixel open-tracking image, all intact.

The purpose is stark once you see the message the way a classifier does. Strip the images and the only readable content is compliant, professionally formatted, opt-in-confirmed commercial mail. Language detection returns French. Structure detection returns "newsletter." Nothing scores.

This is a sharper version of a familiar pattern. Attackers often pad a lure with the impersonated brand's own real marketing links, which at least keeps the camouflage on-topic. Here it is a third party's mail, stolen wholesale, with a live subscriber token still in it. It never needed to relate to the pretext above it, because it was never meant for human eyes. The whitespace exists so nobody scrolls that far.

Two Commercial Layers Waved It Through

The authentication story is short, and it is not the interesting part of this case. The message authenticated. Two DKIM signatures were present, one for the sending domain and one for the bulk sending platform, and both verified at every hop. The spf=fail at the final hop was computed against the recipient's own cloud email gateway, which was the machine relaying the message inward, and that gateway had logged its own SPF pass for the true origin one hop earlier. The dmarc=permerror is a defect in the attacker's own malformed record rather than a detection, and composite authentication still returned a pass.

So the gateway scanned the message and returned a negative threat verdict, and Microsoft then skipped filtering entirely at the lowest possible spam confidence, because the connecting IP was the tenant's own allow-listed gateway. Two commercial layers, both working as designed, neither with anything to catch.

What flagged it was the shape of the thing rather than any single artifact: a first-time sender with no prior contact in either direction, a body whose visible and machine-readable content disagreed completely, and a destination with no history. Our Adaptive AI scored it at 84 percent confidence with credential-theft and VIP-recipient labels and quarantined it nine seconds after it reached the mailbox. One mailbox affected, no clicks.

What to Change Tomorrow

Treat readable body text as a claim, not as evidence. If a message's visible surface is an image and its extractable text is unrelated boilerplate, that mismatch is itself the finding, measurable without OCR. Score domain age directly: anything registered inside the last few days deserves a hard hold regardless of reputation, because reputation cannot exist yet. Expand redirector parameters before scoring a link, so q= is what gets evaluated rather than the wrapper, and make sure the controls aimed at credential theft and malicious URLs judge the destination rather than the string.

CISA's phishing guidance and NIST's definition of phishing make the point this case makes concrete: the attack targets a judgment, not a parser. An unexpected signature request whose text you cannot select is worth ten seconds of suspicion, whatever the link appears to start with.

Indicators of Compromise

TypeIndicatorContext
Emailtxsqfogj@smibaqeuk[.]mugawud[.]comFrom and Reply-To, display name "donotreply"; attacker-owned
Domainsmibaqeuk[.]mugawud[.]comRandom sending subdomain, DKIM signing domain, header From domain
Domainmugawud[.]comAttacker apex domain, verified with the bulk sending platform
DKIM selector3rb5enndqcv5q7cv7ljisz6k7q6w62vnAttacker-controlled signing selector on the sending apex domain
URLhxxps://www[.]google[.]com/url?hl=en&q=hxxps://pristobiz[.]com/erndpreview?id=267e1d7d...506bfb&source=gmail&usg=AOvVaw0c6QuxwhsxiG5q5bUpHGpjThe single CTA, wrapping the entire hero image (id token truncated)
URLhxxps://pristobiz[.]com/erndpreview?id=267e1d7d...506bfbUnwrapped destination; per-recipient identifier token (truncated)
Domainpristobiz[.]comLanding domain, live sixteen minutes before send; Hong Kong registrar, Cloudflare name servers, Lorem ipsum registrant data
IP54[.]240[.]27[.]24Bulk sending platform origin, us-west-2 outbound range
File hash (MD5)dadfbfef31b794a24fbd2cbdfb8fea0433,867-byte PNG carrying the e-signature hero panel; scanned clean
File hash (MD5)0276be368919e6e0a0a7dcc82fdf80c027,368-byte PNG carrying the rasterized recipient address; scanned clean
Subject artifactDC68923709Fabricated document reference prefix, paired with a random eleven-character suffix

MITRE ATT&CK Mapping

TechniqueIDObserved behavior
Phishing: Spearphishing LinkT1566.002Single clickable hero image pointing at an attacker-controlled landing page
Acquire Infrastructure: DomainsT1583.001Landing domain registered sixteen minutes before send, junk registrant data, one-year minimum term
User Execution: Malicious LinkT1204.001Rasterized call to action instructing the recipient to click through to review a document
Masquerading: Match Legitimate Name or LocationT1036.005Redirector wrapper leading with a trusted apex domain; generic unbranded e-signature panel
Email Attack of the Day is a daily series from IRONSCALES spotlighting real phishing attacks caught by Adaptive AI and our community of 35,000+ security professionals. Each post breaks down a real attack. What it looked like, why it worked, and what to do about it.

Related attacks

Attack What happened
Nothing to Click: A QR Code Hidden Inside an Attached EmailA voicemail notification arrived as a single image carrying the recipient's own corporate logo.
The Fireflies Meeting Recap That Never Happened: Dual-Brand Impersonation via Amazon SESA phishing campaign combined Fireflies.ai meeting recap templates with Microsoft Teams branding to target a financial controller.
The Law Firm Name That Used Invisible Characters to Pass AuthenticationA phishing email impersonating Alston & Bird LLP used homoglyph characters in the display name and rode Google Drive sharing infrastructure to pass SPF.
The Procore Footer Was Real. The Document Was Not.Every link scanner called the Procore and ExxonMobil URLs clean.
When 'Release from Quarantine' Is the AttackA fake quarantine digest weaponized email security workflows, embedding JWT tokens in 'Allow' and 'Manage' buttons while masking one link's true...

Explore More Articles

Say goodbye to Phishing, BEC, and QR code attacks. Our Adaptive AI automatically learns and evolves to keep your employees safe from email attacks.