Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • About Bonfire
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org  ·  activity timestamp 2 days ago

Oh well that's fucking clever. A threat actor is sending out phishing emails pretending to be SendGrid, and explaining that all their emails will include "Support ICE" banners in order to trigger ragebait clicks through to the phishing kit.

#threatintel

https://www.linkedin.com/posts/simokohonen_ragebait-as-a-phishing-tactic-a-threat-activity-7415349853754638336-gcCu?utm_source=social_share_send&utm_medium=member_desktop_web&rcm=ACoAABIZhqYBjXCQuV7JX7N_3xlpxZY6alHZ77o

Ragebait as a phishing tactic.. a threat actor pretending to be SendGrid is sending out phishing emails with the note: '..We will be adding a "Support ICE" donation button to the footer of every… | Simo Kohonen

Ragebait as a phishing tactic.. a threat actor pretending to be SendGrid is sending out phishing emails with the note: '..We will be adding a "Support ICE" donation button to the footer of every email sent through our platform'. Feels like the de facto way for phishing people was always trying to lure people with something pleasant, like a list of Christmas bonuses for the year - but psychology has known this effect for a long time, i.e. losing $100 hurts more than finding $100 feels good, or in this case, appearing to support ICE hurts more than knowing the bonuses of the IT department feels good. Still, I feel like this is a bit too over the top.. what do you think? 😆
Screencap showing the phishing email and button.
Screencap showing the phishing email and button.
Screencap showing the phishing email and button.
  • Copy link
  • Flag this post
  • Block
2¢
2¢
@Qbitzerre@unbound.social replied  ·  activity timestamp yesterday

@neurovagrant huh. I thought it was a warning about sea level rise.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp yesterday

@Qbitzerre *rimshot*

  • Copy link
  • Flag this comment
  • Block
Caspar C. Mierau
Caspar C. Mierau
@leitmedium@tldr.nettime.org replied  ·  activity timestamp 2 days ago

@neurovagrant @monoxyd Got that one, too. This is a huge campaign. They pretended to add an lgbtq banner before. Probably the new strategy is "rage phishing". https://tldr.nettime.org/@leitmedium/115865040267681231

  • Copy link
  • Flag this comment
  • Block
Aunty
Aunty
@AuntyRed@aus.social replied  ·  activity timestamp 2 days ago

@neurovagrant fuck. I would definitely fall for that one

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@AuntyRed Stay frosty out there. It's a great time for bastards.

  • Copy link
  • Flag this comment
  • Block
Li ~ Crystal System
Li ~ Crystal System
@Li@tech.lgbt replied  ·  activity timestamp 2 days ago

@neurovagrant im curious is this a targeted attack only at those who aren't cool with horrendous shit being done to people on a daily basis in the name of some imaginary line in the sand

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@Li nah it's wider than that - there are legit samples trying to ragebait the rigth as well

  • Copy link
  • Flag this comment
  • Block
ftg
ftg
@ftg@mastodon.radio replied  ·  activity timestamp 2 days ago

@neurovagrant
Hah, they are playing both sides on this.
The previous variant talked about a Black Lives Matter footer for a month.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@ftg Yep I've now seen "Support LGBT+" variants as well as general technical ones. Definitely a wider campaign than at first glance.

  • Copy link
  • Flag this comment
  • Block
Jamie McCarthy
Jamie McCarthy
@jamiemccarthy@ruby.social replied  ·  activity timestamp 2 days ago

@neurovagrant @ftg The bad guys have been stomping around Sendgrid's servers for at least eleven months. I've probably gotten over 100 of them. Here's my thread: https://ruby.social/@jamiemccarthy/115728934673241939

  • Copy link
  • Flag this comment
  • Block
Bellycan
Bellycan
@pelicangut@aus.social replied  ·  activity timestamp 2 days ago

@neurovagrant same scam but different targets, previous I've seen include threatening Pride banners, commemorating a trans women's death, celebrating Black Lives Matter, to trigger MAGA types. I've been wondering what the converse would be so thanks 🙂

  • Copy link
  • Flag this comment
  • Block
Mike Sheward
Mike Sheward
@SecureOwl@infosec.exchange replied  ·  activity timestamp 2 days ago

@neurovagrant @Viss hah i got this one too

https://infosec.exchange/@SecureOwl/115866328698356357

  • Copy link
  • Flag this comment
  • Block
comrad 🇪🇺
comrad 🇪🇺
@comrad@mastodon.social replied  ·  activity timestamp 2 days ago

@neurovagrant why would someone want to donate to a government institution? Isnt that what taxes are for?

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@comrad The emotional manipulation involve specifically targets irrational actors, so trying to make sense of it is crazymaking.

  • Copy link
  • Flag this comment
  • Block
nyanbinary
nyanbinary
@nyanbinary@infosec.exchange replied  ·  activity timestamp 2 days ago

@neurovagrant I fucking hate this world, man...

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@nyanbinary yup. Been swearin all morning about this.

  • Copy link
  • Flag this comment
  • Block
Walker
Walker
@Walker@infosec.exchange replied  ·  activity timestamp 2 days ago

@neurovagrant That is innovative. Got to give them props for the grift. Still hope non of my users fall for it.

  • Copy link
  • Flag this comment
  • Block
Rich Puchalsky  ⩜⃝
Rich Puchalsky ⩜⃝
@richpuchalsky@mastodon.social replied  ·  activity timestamp 2 days ago

@neurovagrant

A victimless crime. No actual human beings will be harmed

  • Copy link
  • Flag this comment
  • Block
CM Thiede
CM Thiede
@cmthiede@social.vivaldi.net replied  ·  activity timestamp 2 days ago

@neurovagrant when opportunity knocks

  • Copy link
  • Flag this comment
  • Block
Aral Balkan
Aral Balkan
@aral@mastodon.ar.al replied  ·  activity timestamp 2 days ago

@neurovagrant s/clever/evil/

  • Copy link
  • Flag this comment
  • Block
Intaglio Whitegraven
Intaglio Whitegraven
@Intaglio_Dragon@furry.engineer replied  ·  activity timestamp 2 days ago

@neurovagrant I wonder whether anyone on their team has extensive social media management experience. Optimizing posts to maximize engagement, usually through rage-bait, has been a thing there for years. It's one of the worst aspects (in my opinion) of algorithmic social media, and it should not be allowed to catch on in other industries.

  • Copy link
  • Flag this comment
  • Block
Ari "Two Holidays" Jackson
Ari "Two Holidays" Jackson
@arisummerland@beige.party replied  ·  activity timestamp 2 days ago

@neurovagrant Daaaaang they're getting crafty!

  • Copy link
  • Flag this comment
  • Block
GJ Groothedde 🇪🇺
GJ Groothedde 🇪🇺
@Eetschrijver@mastodon.social replied  ·  activity timestamp 2 days ago

@neurovagrant Very clever, very evil.

  • Copy link
  • Flag this comment
  • Block
BeeCycling
BeeCycling
@beecycling@wandering.shop replied  ·  activity timestamp 2 days ago

@neurovagrant Peak social engineering.

  • Copy link
  • Flag this comment
  • Block
Matthew
Matthew
@matthew@famichiki.jp replied  ·  activity timestamp 2 days ago

@neurovagrant 👋 I have also been receiving these messages. I have sent you the ones I still have as an attachment to the email you shared in this thread.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@matthew thank you!

  • Copy link
  • Flag this comment
  • Block
Matt Hardy 3.11 for Workgroups
Matt Hardy 3.11 for Workgroups
@technicaladept@techhub.social replied  ·  activity timestamp 2 days ago

@neurovagrant I could see myself falling for that.

  • Copy link
  • Flag this comment
  • Block
Craig McDaniel
Craig McDaniel
@craigify@mastodon.sdf.org replied  ·  activity timestamp 2 days ago

@neurovagrant

I've been receiving these phishing emails for a while now. I saw this one this morning!

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@craigify Any chance you can forward-as-attachment to me? I'd love to get the email headers and content.

icampbell@domaintools.com

  • Copy link
  • Flag this comment
  • Block
Craig McDaniel
Craig McDaniel
@craigify@mastodon.sdf.org replied  ·  activity timestamp 2 days ago

@neurovagrant

Sure. I just sent you an email with a txt file that contains the SendGrid email I received.

Please share any insights!

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@craigify Absolutely will do! Thank you!

  • Copy link
  • Flag this comment
  • Block
EasyOSX
EasyOSX
@EasyOSX@mstdn.social replied  ·  activity timestamp 2 days ago

@neurovagrant 🤯

  • Copy link
  • Flag this comment
  • Block
Feike 🇪🇺🇳🇱 🚫👑
Feike 🇪🇺🇳🇱 🚫👑
@feike@toot.community replied  ·  activity timestamp 2 days ago

@neurovagrant so: DO NOT CLICK SETTINGS, because it is fake

  • Copy link
  • Flag this comment
  • Block
mks
mks
@swieton@hachyderm.io replied  ·  activity timestamp 2 days ago

@neurovagrant I’ve gotten these from other email providers as well. The email looked legit based on headers (DMARC, SPF.)

  • Copy link
  • Flag this comment
  • Block
Drew Scott Daniels
Drew Scott Daniels
@drewdaniels@mastodon.online replied  ·  activity timestamp 2 days ago

@neurovagrant I saw one two weeks ago about having rainbow templates on all customer emails to support lgbtq+ rights unless you click the link.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@drewdaniels You wouldn't happen to have the email headers or content from that email, would you?

:D

  • Copy link
  • Flag this comment
  • Block
Drew Scott Daniels
Drew Scott Daniels
@drewdaniels@mastodon.online replied  ·  activity timestamp 2 days ago

@neurovagrant I can’t seem to find that one, but I got a new one this morning about Sendgrid’s authentication changing to sinch by the end of the month. From “Sendgrid” but the from address was noreply at nysar.org

Email saying: Migration to Sinch Authentication  We're writing to inform you that we're migrating our authentication system to Sinch. This change will improve security and provide better integration capabilities for your applications.  Starting January 15, 2026, all API requests will need to use Sinch authentication credentials instead of your current API keys.  Get Started  Your existing API keys will continue to work until January 30, 2026, giving you time to complete the transition.  If you have any questions about this migration, please contact our support team. Documentation | Support | Account Settings
Email saying: Migration to Sinch Authentication We're writing to inform you that we're migrating our authentication system to Sinch. This change will improve security and provide better integration capabilities for your applications. Starting January 15, 2026, all API requests will need to use Sinch authentication credentials instead of your current API keys. Get Started Your existing API keys will continue to work until January 30, 2026, giving you time to complete the transition. If you have any questions about this migration, please contact our support team. Documentation | Support | Account Settings
Email saying: Migration to Sinch Authentication We're writing to inform you that we're migrating our authentication system to Sinch. This change will improve security and provide better integration capabilities for your applications. Starting January 15, 2026, all API requests will need to use Sinch authentication credentials instead of your current API keys. Get Started Your existing API keys will continue to work until January 30, 2026, giving you time to complete the transition. If you have any questions about this migration, please contact our support team. Documentation | Support | Account Settings
  • Copy link
  • Flag this comment
  • Block
Santa Caws
Santa Caws
@cR0w@infosec.exchange replied  ·  activity timestamp 2 days ago

@neurovagrant @drewdaniels share with the class plz neodog_glasses_bottom

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

@cR0w @drewdaniels you know it!

  • Copy link
  • Flag this comment
  • Block
Krypt3ia
Krypt3ia
@krypt3ia@infosec.exchange replied  ·  activity timestamp 2 days ago

@neurovagrant I'll take stupid human tricks for 500 Alex.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

I hate scumbags like this, but I have to have some respect for decent craft.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

So here's the historical pDNS and domain data for sender domains in the headers of these emails from the samples I have.

SendGrid UPNs have been a bust so far, but guessing the attack isn't something to really write home about, but I'd like to see this group in particular inconvenienced for the ragebait aspect.

#threatintel

https://drive.proton.me/urls/V2AGD9P57W#MqEEZYyRVjmI

Proton Drive

Securely store, share, and access your important files and photos. Anytime, anywhere.
  • Copy link
  • Flag this comment
  • Block
Asbestos
Asbestos
@Asbestos@pnw.zone replied  ·  activity timestamp 2 days ago

@neurovagrant
Someone needs to do this to target MAGA. Just say "Your [gun related thing] will not include [something'woke'] and click to opt out and also include a feedback link. No way is MAGA going to pass up a chance to tell some lefty what for.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

Inclusion of a domain doesn't necessarily indicate malicious actions on the part of the domain's owners.

  • Copy link
  • Flag this comment
  • Block
Ian Campbell 🏴
Ian Campbell 🏴
@neurovagrant@masto.deoan.org replied  ·  activity timestamp 2 days ago

Guessing it's a mix of compromised domains, and active domains with an exploitable misconfiguration common to cloudflared domains that opens their relay up, though I don't know one off the top of my head.

  • Copy link
  • Flag this comment
  • Block
αxel simon ↙︎↙︎↙︎
αxel simon ↙︎↙︎↙︎
@axx@mstdn.fr replied  ·  activity timestamp 2 days ago

@neurovagrant Wow, that's annoyingly clever.

In unrelated news, i was reflecting this morning on how "sad sack of shit" was probably one of my favourite insults.

  • Copy link
  • Flag this comment
  • Block
Zack Whittaker
Zack Whittaker
@zackwhittaker@mastodon.social replied  ·  activity timestamp 2 days ago

@neurovagrant i often find myself both disgusted at the depravity of some cybercriminals, yet impressed by their technical skill.

  • Copy link
  • Flag this comment
  • Block
Taggart
Taggart
@mttaggart@infosec.exchange replied  ·  activity timestamp 2 days ago

@zackwhittaker @neurovagrant

Dril tweet

Issuing a correction on a previous post of mine, regarding the terror group ISIL. you do not, under any circumstances, "gotta hand it to them."
Dril tweet Issuing a correction on a previous post of mine, regarding the terror group ISIL. you do not, under any circumstances, "gotta hand it to them."
Dril tweet Issuing a correction on a previous post of mine, regarding the terror group ISIL. you do not, under any circumstances, "gotta hand it to them."
  • Copy link
  • Flag this comment
  • Block
hrbrmstr 🇺🇦 🇬🇱 🇨🇦
hrbrmstr 🇺🇦 🇬🇱 🇨🇦
@hrbrmstr@mastodon.social replied  ·  activity timestamp 2 days ago

@neurovagrant #ty for reading the toxic positivity site so i do not have to 🙃

and i def tip my hat to those threat actors. brilliant emotional manip!

  • Copy link
  • Flag this comment
  • Block

BT Free Social

BT Free is a non-profit organization founded by @ozoned@btfree.social . It's goal is for digital privacy rights, advocacy and consulting. This goal will be attained by hosting open platforms to allow others to seamlessly join the Fediverse on moderated instances or by helping others join the Fediverse.

BT Free Social: About · Code of conduct · Privacy ·
Bonfire social · 1.0.1-beta.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Code of Conduct