Analysing Targeted Spearphishing: Social Engineering, Domain Rotation, and Credential Theft
Expert: Charlie Kelly
Role: SOC Analyst
Specialises in: Security Operations
The Stripe OLT SOC has identified a sophisticated Spearphishing campaign targeting senior employees, particularly those in C-Suite and leadership positions.
Actors behind this campaign are leveraging tailored emails that impersonate internal HR communications, via a shared document in OneDrive, to trick recipients into entering corporate credentials.
Key Details
Figure 1: Example Email Body Content
Figure 2: Example Credential Phishing Page
Technical Details
Our analysis of campaign infrastructure shows that the actor is leveraging multiple providers across delivery, registration, DNS, and hosting. Specifically:
Anti-Detection Techniques
We have also observed the actor behind this campaign using obfuscated button text to bypass detection methods. When the initial email is viewed in Light Mode, the buttons appear as “Open” and “Share”.
In Dark Mode, concealed padding becomes visible, exposing randomised alphanumeric strings such as twPOpenHuxv and gQShareojxYI. This breaks up high value trigger words like “Open” and “Share,” reducing the likelihood of detection by secure email gateways that apply string or regex based rules.
Figure 3: Example Email Body Content, Light Mode
Figure 4: Example Email Body Content, Dark Mode
Recommended Actions
To reduce exposure and strengthen resilience internally to threats like this, organisations should take the following steps – these aren’t optional safeguards, they’re the essentials:
For Security & IT TeaMs
While awareness is the first line of defence, this campaign is sophisticated enough that relying solely on end-user caution is not enough. Security and IT teams should proactively hunt for IOCs and check whether their organisation has already been targeted.
Our SOC analysts recommend starting with targeted hunting queries and blocking domains linked to this campaign.
Sentinel Hunting Query
Run the following KQL query in Sentinel to detect emails that match the observed subject lines:
EmailEvents
| where Subject contains "FIN_SALARY"
| where EmailDirection == "Inbound"
| project Timestamp, RecipientEmailAddress, SenderMailFromDomain, Subject, ConfidenceLevel, NetworkMessageId, EmailAction
Indicators of Compromise (IOCs)
The following is a list of domains have been used for email sending:
letzdoc[.]com
hr-fildoc[.]com
docutransit[.]com
seamlessshare[.]com
filershare[.]com
sharinfile[.]com
mysharedfiling[.]com
filersharing[.]com
documentsforall[.]com
seenfile[.]com
sharedserve[.]com
documentmagnet[.]com
documentpocket[.]com
documentreplublic[.]com
fileagenda[.]com
onpointcollab[.]com
sharedsheet[.]com
ventordocs[.]com
sidedocuments[.]com
sparfile[.]com
filealertsphere[.]com
notifydocshub[.]com
levitateo[.]com
syncdocnotify[.]com
pingarchive[.]com
spdocsync[.]com
jointcomet[.]com
bizchrod[.]com
mergepads[.]com
huddledoc[.]com
paneldocument[.]com
stratusedit[.]com
blenddocs[.]com
wesharedocs[.]com
baccatelo[.]com
casualdocs[.]com
filecomrade[.]com
outzanycy[.]com
colabwithme[.]com
pipelinedocs[.]com
interactdocs[.]com
signifile[.]com
foliodocs[.]com
grouperdocs[.]com
takshare[.]com
docleash[.]com
docphaser[.]com
docstackk[.]com
unfolddocs[.]com
bluedotshare[.]com
collabeam[.]com
suprshare[.]com
karrofile[.]com
candiddocs[.]com
vivedocs[.]com
squadsdocs[.]com
doculibr[.]com
docsinsertio[.]com
docutug[.]com
quotadocu[.]com
shareinsync[.]com
Spearphishing is evolving, and adversaries are investing in more targeted, evasive tactics.
If you’d like support in strengthening your detection and response capabilities, book a free discovery session with our team. We’ll help you assess where you stand, and help you understand how to get ahead.










