Past workSOC Analyst Trainee, SOCByte, February – April 2026.

Tracing a reply-bait phishing campaign that passed every automated check

A quarantined email passed SPF/DKIM and sandbox detonation and carried no links or attachments. Pivoting on it uncovered a 90-day, multi-domain reply-bait campaign.

  • Scope foundAbout 90 days, multiple sending domains, one abused relay
  • ResponseRetro-hunt, infrastructure blocked, awareness, vendor report

Tracing a reply-bait phishing campaign that passed every automated check

The email that looked fine

The starting point was one quarantined email. It had passed SPF and DKIM authentication, passed sandbox detonation, and contained no links and no attachments. By every automated measure, nothing was wrong with it.

That was the interesting part. A message with nothing to detonate and valid authentication gives automated tools very little to work with, so I treated the message itself as a lead rather than a verdict.

Investigation

How one quarantined email led to a campaign

  1. One quiet emailQuarantined. Passed SPF/DKIM and sandbox detonation. No links, no attachments.
  2. PivotSender alias, source IP, and subject line used as search keys.
  3. Campaign scopeAbout 90 days, multiple sending domains, rotating proverb-based lures, one abused relay in a European datacenter.
  4. ResponseTenant retro-hunt, follow-on infrastructure blocked, targeted awareness, detection-gap report to the email security vendor.
Investigation flow. Infrastructure, domains, and lure text are withheld.

I pivoted on the sender alias, the source IP, and the subject line. That widened one message into a campaign that had been running for about 90 days across multiple sending domains, using rotating proverb-based lures and relaying through abused infrastructure in a European datacenter.

Every sending IP and domain scored clean on VirusTotal. Reputation was not going to catch this one; the pattern across messages was the evidence.

What it was

I identified it as a reply-bait, or conversation-hijack, precursor. The first message is harmless by design. The phishing payload arrives only after a recipient replies and a conversation exists, which is exactly why the first message has nothing malicious in it to find.

Response

  • Ran a retro-hunt sweep across the tenant for related messages.
  • Blocked the follow-on infrastructure.
  • Initiated targeted user awareness for the people the campaign was reaching.
  • Submitted the analysis to Trend Micro Email Security as a detection-gap report, so the vendor could improve its engine.

What I took from it

  • A clean reputation score is a data point, not a verdict.
  • When the content is empty on purpose, look at the pattern: who sends, from where, and how the lures change.
  • Reporting a gap to the vendor is part of the fix. Blocking this campaign helps one tenant; a better engine helps everyone using it.

Search the site