Q3 2026 phishing campaigns abused trusted email infrastructure, including Amazon Simple Email Service (SES), and DKIM-aligned sender domains to make fraudulent messages pass common authentication checks. The emails used overdue-payment, invoice, antivirus-renewal, and banking/PSD2-consent lures, while hiding malicious or fraudulent content behind multi-stage redirect chains rather than attachments or obviously suspicious initial URLs.
One German invoice-themed campaign used browser fingerprinting, hidden requests, decoy content, iframes, and obfuscated code before redirecting analysis traffic to OpenSea, indicating cloaked crypto or NFT fraud. A separate Romanian operation impersonated BCR S.A., using an IPv6-mapped IP-literal URL and redirects to target banking credentials; defenders should assess the full click path and post-load behavior because SPF, DKIM, and DMARC validate sender authorization, not the legitimacy of the request or final destination.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In Q3 2026, a Romanian-language phishing campaign impersonated BCR S.A. and claimed that PSD2-consent renewal was needed to avoid restricted banking access. It used the DKIM-aligned but unrelated xmasbrick[.]com domain, an IPv6-mapped IP-literal URL representing 103[.]193[.]179[.]223, and a redirect to web5-4s4c-online-garantibbva[.]vibtee[.]com/ro/; researchers assessed it as credential theft.
In Q3 2026, an antivirus-renewal phishing lure claimed recipients had "631 dangerous viruses," threatened account closure, and offered a discount to create urgency. The flow used 31-59-175-195[.]syd[.]nbn[.]aussiebb[.]net and loadswage[.]com as redirect infrastructure, while eightindigostove[.]com hosted an unsubscribe path.
In Q3 2026, a German-language overdue-payment lure was delivered through Amazon Simple Email Service using the DKIM-aligned moolaah[.]com domain. Its redirect chain used browser and time-zone fingerprinting, decoy content, hidden elements, and obfuscated code before redirecting analysis traffic to opensea[.]io, indicating possible cloaked crypto or NFT fraud.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.