Expert Intel

Analysing Targeted Spearphishing: Social Engineering, Domain Rotation, and Credential Theft

Published: August 27, 2025
Updated: December 02, 2025

Expert: Charlie Kelly

Role: Security Analyst

Specialises in: Security Operations

What you will learn:
In this Expert Intel, our Principal Security Analyst, breaks down how a new spearphishing campaign operates - and the practical steps organisations must take to recognise, resist, and respond to these types of attack.
Emails observed feature anti-detection techniques such as hidden characters and high-reputation external links, as well as single use phishing URLs that self-destruct once accessed.

The Stripe OLT SOC has identified a sophisticated Spearphishing campaign targeting senior employees, particularly those in C-Suite and leadership positions.

Actors behind this campaign are leveraging tailored emails that impersonate internal HR communications, via a shared document in OneDrive, to trick recipients into entering corporate credentials.

Targets: Executives and senior leadership across multiple industries
Email Content: Subject lines reference “Salary amendment” or “FIN_SALARY” and pose as OneDrive document-sharing notifications.
Credential Theft Page: The link leads to a convincing Microsoft Office/OneDrive login page, which harvests credentials. Both the email body and phishing page are customised with the recipient’s name and company details to enhance credibility.
Delivery Method: Emails are sent via Amazon Simple Email Service (SES) infrastructure. The actor is rotating between many sending domains and subdomains to evade detection. To date, approximately 80 domains have been identified as part of this campaign.
Campaign Tactics: We have observed the actor “warming up” inboxes by sending an initial benign email days before the phishing attempt. Emails observed feature anti-detection techniques such as hidden characters and high-reputation external links, as well as single use phishing URLs that self-destruct once accessed.
Financial salary amendment document received via email from Stripe OLT platform.

Our analysis of campaign infrastructure shows that the actor is leveraging multiple providers across delivery, registration, DNS, and hosting. Specifically:

Amazon SES – used for email delivery.
Cloudflare – observed as a frequent DNS/nameserver provider for related domains.
Akamai Cloud (formerly Linode) – identified as a hosting provider for phishing infrastructure.
Mat Bao Corporation – the most common registrar, with the majority of domains registered here.
Web Commerce Communications Limited (WebNic.cc) – additional registrar observed.
Luxhost – additional DNS/nameserver provider identified.

We have also observed the actor behind this campaign using obfuscated button text to bypass detection methods. When the initial email is viewed in Light Mode, the buttons appear as “Open” and “Share”.

In Dark Mode, concealed padding becomes visible, exposing randomised alphanumeric strings such as twPOpenHuxv and gQShareojxYI. This breaks up high value trigger words like “Open” and “Share,” reducing the likelihood of detection by secure email gateways that apply string or regex based rules.

To reduce exposure and strengthen resilience internally to threats like this, organisations should take the following steps – these aren’t optional safeguards, they’re the essentials:

Awareness for executives and assistants – Ensure that those most likely to be targeted understand this campaign. The actor is using realistic “salary amendment” subject lines and personalised company details to increase credibility.
Scepticism around unexpected documents – Remind staff to be cautious when receiving links or documents relating to HR, payroll, or salary matters, particularly when sent externally.
Reporting suspicious emails – Make it clear how to escalate suspicious messages quickly within your business. The faster these are reported to your security resource, the quicker they can take action to protect others.
Support staff training – Executive assistants and close colleagues are also high-value targets. Ensure they receive the same level of awareness training and support as C-suite members.

While awareness is the first line of defence, this campaign is sophisticated enough that relying solely on end-user caution is not enough. Security and IT teams should proactively hunt for IOCs and check whether their organisation has already been targeted.

Our SOC analysts recommend starting with targeted hunting queries and blocking domains linked to this campaign.

Run the following KQL query in Sentinel to detect emails that match the observed subject lines:

The following is a list of domains have been used for email sending:


Spearphishing is evolving, and adversaries are investing in more targeted, evasive tactics.

If you’d like support in strengthening your detection and response capabilities, book a free discovery session with our team. We’ll help you assess where you stand, and help you understand how to get ahead.

Our latest expert Intel

  • July 19, 2026
    Read full article
  • July 15, 2026
    Read full article
  • May 13, 2026
    Read full article
  • July 9, 2026
    Read full article
  • April 14, 2026
    Read full article
  • April 10, 2026
    Read full article
  • April 2, 2026
    Read full article
  • Cyber Background
    March 24, 2026
    Read full article
  • notepad compromise
    April 1, 2026
    Read full article
  • M365
    February 3, 2026
    Read full article
  • Person using a laptop with the Google search homepage open
    July 9, 2026
    Read full article
  • January 20, 2026
    Read full article