A note on the indicators below: all hostnames and URLs in this post are defanged (hxxps[:]//, [.]) so nothing in the page is clickable. Re-fang them only inside an isolated analysis environment. The detection rules in…
A single spoofed Ledger email, a phishing-tracker pipeline, a vision model that kept us honest and three distinct pieces of attacker infrastructure, two of them still live at time of writing. The…
1. Executive Summary On 2026-08-27 at 14:30 UTC, a UK recipient received a phishing email spoofing an Intuit QuickBooks payment notification. The email claimed a payment had been deposited and invited the recipient to…