Threat actors are increasingly abusing trusted SaaS platforms and email authentication to deliver high-conviction scam lures that evade traditional filtering. Trend Micro reported a targeted spam operation that weaponizes Atlassian Cloud features to send messages that pass common checks (e.g., SPF/DKIM) due to the strong reputation of SaaS sender domains; the campaign is multilingual and aims to redirect government and corporate recipients to fraudulent investment landing pages using Keitaro TDS, with attackers creating multiple Atlassian instances for resilience and scale.
Separately, Forcepoint X-Labs described phishing emails impersonating the US Social Security Administration that deliver a .cmd script to weaken Windows defenses (including disabling SmartScreen, removing Mark-of-the-Web, and using Alternate Data Streams) before silently installing ConnectWise ScreenConnect as a remote-access backdoor (including a hardcoded callback configuration). Related research highlighted DKIM replay attacks, where adversaries forward legitimate, DKIM-signed vendor emails (e.g., PayPal/DocuSign-style invoices and dispute notices) so the unchanged content continues to validate and can pass DMARC, increasing inbox placement and user trust for follow-on social engineering.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that in early 2026 attackers were abusing Amazon Simple Email Service to send authenticated phishing and business email compromise messages that passed SPF, DKIM, and DMARC checks. The campaigns used lures such as fake DocuSign notices and forged invoice threads, with access often enabled by exposed AWS IAM keys leaked in public repositories, images, or storage.
Cisco Talos reported that attackers abused the n8n workflow automation platform from October 2025 through March 2026, using exposed webhooks on trusted n8n cloud subdomains to host phishing flows, tracking pixels, and malware delivery pages. Talos described campaigns delivering a fake OneDrive lure that installed a modified Datto RMM tool and a malicious MSI that deployed ITarian Endpoint Management as a backdoor.
Cisco Talos reported that attackers were abusing trusted SaaS notification pipelines, especially GitHub and Jira, by embedding phishing and scam lures in commit messages, invitations, and project fields so the platforms themselves sent authenticated emails that passed SPF, DKIM, and DMARC checks. Talos characterized the method as 'Platform-as-a-Proxy' and said telemetry on Feb. 17, 2026 showed likely abuse making up about 2.89% of observed GitHub email volume.
Trend Micro disclosed a sophisticated campaign abusing Atlassian Cloud’s trusted email infrastructure to target government and corporate users with multilingual scam emails. The campaign used Atlassian and AWS-hosted delivery plus Keitaro TDS redirect chains to increase credibility, scale, and resilience while complicating detection.
Kaseya’s INKY researchers reported that attackers were abusing legitimate invoice and dispute-notification workflows from trusted services to embed scam content in vendor-generated emails. The attackers then forwarded the unchanged DKIM-signed messages to victims, allowing the emails to pass DKIM and DMARC checks and evade common email security filters.
Trend Micro reported that a targeted spam campaign leveraging Atlassian Cloud infrastructure became prominent between late December 2025 and January 2026. The activity used Jira Automation and disposable Jira Cloud instances to send scam emails that could pass SPF/DKIM checks and redirect targets to fraudulent investment schemes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourceblog.talosintelligence.com
Open sourcecybersecuritynews.com
Open sourceblog.knowbe4.com
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.