Phishing is infiltrating through legitimate email channels. Instead of employing obvious malicious addresses, attackers send ordinary alerts, invoices, and renewal notices that entice users into web-based traps. In Q3 2026, testing revealed phishing samples utilizing this model.
The browser and time zone information were collected, followed by an unlinked request that led to OpenSea, indicating a cloaked crypto or NFT fraud route, rather than malware delivery. The broader lesson is aligned with blob URL phishing techniques: attackers are increasingly placing harmful content later in the journey, where conventional email checks have less visibility.
Indicators of compromise (IoCs): Type Indicator Description Hostname 31-59-175-195.sydney.nbn.australianbbnet Redirect infrastructure used in the antivirus renewal scareware phishing flow Domain loadswage.com Redirect infrastructure associated with the antivirus renewal phishing sample Domain eightindigostove.com Domain hosting the unsubscribe path in the antivirus renewal phishing sample Sender domain moolaah.com DKIM-aligned sender domain used for the cloaked overdue-payment invoice lure URL website-2df62808.mvplineup.com/audacity/underside First-stage cloaking page used in the invoice phishing redirect chain Domain opensea.io Final destination reached after the cloaking and browser-fingerprinting stage Sender domain xmasbrick.com DKIM-aligned but unrelated sender domain used in the Romanian banking phishing email URL hxxp://[0000:0000:0000:0000:0000:FFFF:67C1:B3DF]/11881659 IPv6-mapped IP-literal URL embedded in the banking phishing message IPv4 address 103.193.179.223 IPv4 address represented by the IPv6-mapped URL notation URL web5-4s4c-online-garantibbva.vibtee.com/ro/ Redirect destination in the Romanian PSD2 banking phishing chain











