Executive Summary
A high-severity phishing campaign utilizes social engineering under the guise of legal notifications to harvest user credentials. The attack leverages legitimate Google infrastructure, ensuring it passes standard email authentication checks like SPF, DKIM, and DMARC. By impersonating professional legal entities through personal Gmail accounts, the attackers create a sense of urgency that pressures recipients into clicking malicious links.
Technically, the campaign employs URL shorteners (specifically short.gy) to bypass reputation-based link scanners. These shortened URLs redirect to a privacy-protected attacker domain (chongdaotang[.]net) registered in late 2023. The use of mass-BCC delivery hides the scale of the campaign while maintaining the appearance of a personalized legal notice.
This threat is particularly effective against organizations relying solely on traditional Security Email Gateways (SEGs) that do not follow redirect chains to the final destination. The urgency of a 'legal threat' is designed to cause high-pressure decision-making, increasing the likelihood of successful credential theft across multiple sectors.
