A massive email fraud scheme utilized fake CEO emails and invoices to trick employees into making nearly $50,000 in payments. Instead, it relied on regular emails to deceive recipients. The perpetrators sent out over one million messages between August 3 and 5, primarily targeting users in the United States, which made up 87.7% of the campaign.
Indicators of compromise (IoCs): - Domain: service-nowinc[. ]com - Type: Domain impersonating ServiceNow - Email address: gomez@service-nowinc[. ]com - Type: Email address associated with a bank account - Email address: notifications@uinsure[.]co[.
]uk - Type: Sender email address used to send campaign emails - Email address: info@tivityhealth[. ]com - Type: Sender email address used to send campaign emails - Email address: no-reply@lumalisboa[. ]com - Type: Sender email address used to send campaign emails - Email address: noreply@mctci[. ]com - Type: Sender email address used to send campaign emails - Email address: info@nuf[.]co[.
]jp - Type: Sender email address used to send campaign emails - Email address: info@lohnsteuerhilfe-aktuell-verein[. ]de - Type: Sender email address used to send campaign emails - Email address: info@tovimbatista[. ]pt - Type: Sender email address used to send campaign emails - Email address: contact@eemusicclass[.]co[. ]uk - Type: Sender email address used to send campaign emails - Email address: info@lifeones[.
]com - Type: Sender email address used to send campaign emails - Domain: domainlify[. ]net - Type: Newly registered domain used in the Reply-To address












