threat_intelligence1798 wordsRead on Arc Codex

Inside a Fast-Moving Phishing Campaign Captured by AIDE

Introduction In January 2026, an attacker attempted ~20,000 phishing emails against two distinct victim populations in just two five-minute bursts within an hour – the first was a fake Microsoft OneDrive file-share notification, and the second offered a fake job opportunity. The technique is not new, but this rapid-fire example reminds us that familiar techniques remain effective enough, and inexpensive enough to run, that the pattern is still worth pursuing at scale. AIDE, the Global Cyber Alliance’s honeypot sensor network, captured this activity on January 27, 2026. The sequence was: a single source ran two different lures back-to-back, against two distinct audiences, while a working sending path was still available. In this article, we’ll explore the activity we saw in AIDE, the lures the attackers used, and defensive measures for mail operators, businesses, and job seekers. Scope note: This field report draws on AIDE-observed Simple Mail Transfer Protocol (SMTP) activity and internal enrichment of the sending source, lure content, recipient-domain patterns, and reply-to infrastructure. Specific sender, recipient, and reply-to indicators are not published here, to avoid exposing potential victims or amplifying active infrastructure. The Malicious Traffic Source Both bursts came from a single IPv4 address on a low-cost virtual private server (VPS) hosted by a European provider. Cheap VPS providers are commonly used to launch automated attacks or scans because they’re disposable and fairly anonymous. The address was already present on multiple public blocklists at the time of the activity, meaning other security services had already flagged that IP as bad. Since this attack, public reputation databases have accumulated hundreds of reports against the same address from a wide range of independent sources. The host remained observable during our review period. Nothing here required innovation. Cheap rented infrastructure, a known bad IP address, and a script recycling the same brand impersonations – that’s the entire toolkit. No undiscovered vulnerabilities, no custom malware, no botnets. The barrier to entry is low, and that’s precisely what makes this kind of attack so hard to stop at the source. Burst One: A OneDrive Lure Aimed at South African Businesses AIDE observed roughly 6,020 attempted deliveries in a five-minute window. Each one impersonated a Microsoft OneDrive file-share notification: a one-line claim that a file had been shared via OneDrive Adobe Viewer, followed by a CLICK HERE prompt. Internal enrichment of the linked infrastructure indicated a fake Adobe Viewer credential flow designed to capture Microsoft 365 logins. The recipient list is what makes the campaign worth reading. Of 2,961 unique recipient domains, more than 80% ended in .co.za. The targeting skewed hard toward business email at South African real estate firms, telecoms, and financial services companies. Freemail addresses were a small minority; the list leaned heavily toward organizational and South African business domains. The recipient composition does not look like random spraying. It suggests curation or deliberate selection. The choice of OneDrive as a lure fits a broader pattern. Six days before this activity, Microsoft Threat Intelligence published a deep dive on a resurgent multi-stage adversary-in-the-middle phishing and BEC campaign that uses SharePoint file-sharing workflows to deliver credential-harvesting payloads. The Microsoft team describes the technique as a way to ride trusted Microsoft brand surfaces past mail filters and end-user suspicion. The lure structure observed on January 27 lines up cleanly with that pattern. What the Lure Looks Like To an end user scanning their inbox between meetings, the message reads as routine. The visible body is sparse: a salutation, a one-line OneDrive Adobe Viewer file-share claim, and a CLICK HERE prompt. There is not much persuasion in the body. Just the brand cue, the file-share claim, and the click. The destination page, surfaced through internal enrichment rather than the SMTP capture itself, presented a credential prompt styled to mimic an Adobe Viewer login. Redacted reconstruction based on AIDE-observed SMTP content. Recipient, link destination, and infrastructure indicators have been removed. Burst Two: An Indeed Impersonation Aimed at Personal Inboxes Roughly fifty minutes later, the same source came back. This time the volume was bigger and the audience was different. AIDE observed 14,716 attempted deliveries in another five-minute window. Every recipient address used live.com or msn.com. The lure was a fake job offer. The script was identical across all 14,716 messages: an Indeed-branded note offering “800 a week” for a remote part-time role, signed by a recruiter named Vanessa, asking the recipient to reply for next steps. No link in the body. No attachment. The hook was the reply itself. Redacted reconstruction based on AIDE-observed SMTP content. Recipient, link destination, and infrastructure indicators have been removed. The reply-to address pointed to a typosquat domain – a lookalike of a major U.S. financial services firm’s real domain, with one letter dropped. The lookalike was registered months in advance, already flagged on public reputation lists with a strongly negative score, and configured to receive inbound mail from victims who believed they were negotiating a salary. Bitdefender warned about a closely related pattern six days earlier. Their Antispam Lab documented a wave of fake recruitment emails timed to the early-year hiring surge, impersonating well-known employers and staffing brands and routing victims toward off-platform conversations on apps like WhatsApp and Telegram. The economics line up. January hiring activity gives this kind of lure a receptive audience. Why Two Campaigns from One Source Running two completely different campaigns through the same source within an hour suggests opportunistic rotation across monetization paths while a sending channel is still live. Stolen Microsoft 365 credentials can feed one monetization path. Job-seeker correspondence can feed another, including advance-fee fraud or money-mule recruitment. The mix is more consistent with broad-spectrum sending than with a single targeted intrusion campaign. The Mail Routing Problem Microsoft Recently Highlighted Three weeks before this activity, Microsoft Threat Intelligence published a separate report on phishing actors abusing misconfigured mail routing to spoof legitimate domains. The piece walks through how operators find permissive paths, route messages through them, and pick up domain reputation they did not earn. The activity pattern observed on January 27 fits inside that broader behavior class. The pattern was repeatable: one working sending path, two lure templates, and enough time to push thousands of attempted deliveries in short bursts. The Wider Picture: South Africa as a Target ESET’s H2 2025 Threat Report, released in early 2026, found that phishing accounted for 45.7% of detected cyber threats in South Africa during the reporting period, compared with 32.5% across Africa. In ESET’s telemetry, phishing remained the highest-risk category affecting South African users and organizations. Real estate, telecom, and finance are exactly the verticals where document-sharing workflows are dense and email is still the contract surface. Sales associates routinely handle attachments, share links, and time-sensitive correspondence. A spoofed OneDrive link does not look out of place in that workflow. A Cluster of Real Estate Recipients The most striking detail in the recipient set is the concentration of real estate organizations – a notable cluster of South African real estate businesses, including organizations that operate in overlapping markets. A credential captured in this sector would be sellable: access to listing platforms, property-transaction correspondence, and buyer-seller communications. Real estate remains a high-value fraud target because transactions involve large payments, tight timing, and email-heavy coordination. Pattern Notes Pulling the two bursts together leaves a few observations worth keeping for future reference. - A single sending source ran multiple brand impersonations through the same channel within the same hour. Attribution by infrastructure alone may undercount the distinct campaign types a single sender may be running. - The source was already listed in external reputation data. The campaigns ran anyway. Blocklists help receivers defend; they do not stop senders from trying. - Typosquatted reply-to domains remain a recurring job-scam technique. Pre-positioned lookalikes of financial-services brands keep turning up in this infrastructure, registered well before they are used. - This sample indicates that South African business domains were present in at least one curated-looking target set. Defenders in that sector should treat unexpected OneDrive and SharePoint share notifications as prompts for additional verification, not as routine document traffic. Defensive Takeaways For Mail Operators Audit mail-routing configuration. Actors behind campaigns of this kind are scanning for permissive paths and rotating through them quickly. Properly configured authentication, alignment, and acceptance policies meaningfully reduce the inventory available to them. SPF, DKIM, and DMARC alignment can close a sizable share of the routes these scripts depend on. For South African Businesses Operate as if your domain could already be on a target list. The .co.za concentration in burst one was not random. If your organization handles documents through OneDrive or SharePoint, train staff to verify share links by signing in through the platform directly rather than clicking through the email notification. The lure can look close enough to the real thing to feel routine. For Job Seekers Recruiters who offer vague weekly pay for unspecified remote work, sign with a first name only, and ask you to reply from a personal address are running an old script. Verify any recruiter through the company’s own careers page before exchanging anything, and look closely at the reply-to domain – one missing letter is enough to redirect your response to a fraud inbox. Conclusion Across two five-minute bursts, the source attempted around twenty thousand deliveries against two distinct victim populations in succession. Nothing in the January 27 capture is technically new. What it shows instead is that the old playbook still gets results, and still costs so little to run that people keep using it at scale. AIDE’s value is in making that activity visible in a form defenders and partners can use: timing, targeting, infrastructure, and behavior. Those details can help them understand the pattern, tune controls, and reduce the room these campaigns have to operate. Small improvements in each of those places add up. That visibility can also support a broader question: how effectively does the domain ecosystem respond when malicious or abusive use is identified? GCA’s Domain Trust initiative approaches this from the operator side, looking at DNS abuse-mitigation or management practices and measurable outcomes. The Domain Trust Badge initiative is intended to recognize operators that demonstrate those practices, supporting the broader goal of tackling DNS abuse collectively as an ecosystem issue. References - Microsoft Defender Security Research Team. “Resurgence of a multi-stage AiTM phishing and BEC campaign abusing SharePoint.” Microsoft Security Blog, January 21, 2026. - Alina Bizga. “Hiring Season Is Scam Season: How Fake Recruiters Exploit Job Seekers with Trusted Brand Names.” Bitdefender Hot for Security, January 21, 2026. - Microsoft Threat Intelligence. “Phishing actors exploit complex routing and misconfigurations to spoof domains.” Microsoft Security Blog, January 6, 2026. - ESET. “ESET Threat Report: Phishing and Social Engineering Are The Most Significant Risks for South African Organisations” (covering H2 2025 data, June through November 2025). Press release, February 2026.

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.