The Link Lives in the Attachment: A Multi-Operator Email Evasion Landscape
The Link Lives in the Attachment: A Multi-Operator Email Evasion Landscape
Across three months in early 2026, six email scam operators leaned on the same evasion: the malicious link lived inside the attachment, not the email body. We surveyed hundreds of thousands of attachment-bearing emails over a 90-day window and found the attachment doing the work that inline URLs used to do. A spreadsheet renders a fake insurance quote with a button. A PDF shows a payment receipt and a phone number to call. A signed Apple Wallet pass installs on tap and hides a callback line on its back face. The email body, meanwhile, is empty or bland, giving body-text classifiers and URL-reputation systems nothing to score. Six operator clusters and two emerging novel-format clusters share this one design choice, and it is the choice, not any single domain, that ties them together.
Key Takeaways
- Six distinct operator clusters, plus two emerging novel-format clusters, all move the scam's active surface (a link, a callback number, or executable code) out of the email body and into an attachment.
- The attachment ecosystem sorts into three functional roles: lure carrier (a rendered fake document), payload or executable (code that runs on open), and evasion vehicle (a filter-bypassing container hiding a link or instruction).
- Operators reach for file extensions no consumer software produces, including
.words,.order,.json-as-attachment,.vcf, and Apple Wallet.pkpass, specifically to slip past extension blocklists tuned for.exeand.js. - One CarShield-impersonation vertical rotated 1,110 distinct sender display names using case-shuffling, ligature and separator injection, zero-width characters, and homoglyph corruption of the brand token.
- The durable indicator is behavioral, not atomic: an attachment present alongside an empty body-level click target. The sending domains rotate daily, but the tactic survives rotation.
- Novel persistence surfaced through
.pkpassWallet passes that survive email deletion, and voice-phishing surfaced through inertvoicemail.mp3files paired with a callback number in the subject line.
Background
Email filtering has spent a decade getting good at two things: reading the body text and scoring the links. Attachment-borne delivery is a direct answer to both. If the URL never appears in the message body, a URL-reputation engine has nothing to look up, and a body-text classifier reads a clean or near-empty message. The lure, the link, or the executable code all sit one layer down, inside a file the recipient has to open.
The operators in this window used the full attachment vocabulary. Some files are pure social engineering: a .pdf or .xlsx renders a fake invoice, quote, or receipt, and the click target is a button, a phone number, or a QR code drawn onto the rendered page. Some files are payloads: a .py Python script, an Office macro carrier, or a .pst Outlook archive that loads attacker-controlled mail state when opened. Some files are containers picked to bypass filters: a local .html credential page that opens in the browser without ever crossing a URL filter, or a calendar .ics invite whose meeting description carries the link.
A few of the platforms these operators abuse deserve a plain-English note, because their trusted parent domains are exactly what makes them attractive:
- Object storage buckets on Google Cloud Storage, DigitalOcean Spaces, and Linode Object Storage are public-facing file hosts under reputable parent domains. Scammers park landing pages in short-lived, randomly named buckets because the provider's TLS certificate and well-known parent domain slip past some reputation checks, and a bucket spins up and burns in minutes.
- Cloudflare Workers (
workers.dev) is free developer hosting with instant deploy, TLS, and a reputable parent domain, which makes it a convenient one-shot redirect layer. - Telegraph (
telegra[.]ph) is Telegram's anonymous publishing platform. Anyone can publish a page with no account and no domain of their own, so it gets abused as a throwaway landing page. - cal.com is a legitimate open-source scheduling platform. Because it sends real calendar invites from its own infrastructure, an invite it generates passes authentication cleanly, and the operator hides the payload in the meeting title and description.
- Apple Wallet passes (
.pkpass) are signed bundles that install into the Wallet app on tap. A pass can carry a back-of-pass URL or phone field and persists on the device after the email is deleted.
The impersonated brands span auto-warranty and life-insurance (CarShield, FidelityLife, New York Life), banking and payments (Charles Schwab, Wells Fargo, HSBC), Apple order tracking, and, in one thread, the Kenyan insurer CIC Insurance Group. In the CIC case the operator used the insurer's name and a CIC_Asset_Management_Team.pdf filename as the pretext while sending from an unrelated throwaway domain. The insurer's own systems are not involved.
Discovery and Infrastructure
This survey came out of field-driven discovery rather than a seed IOC. Building an extension histogram across attachment-bearing detections, then mapping the top sending domains behind each over-represented extension, surfaced six operators in a single pass plus the two emerging clusters. The functional-role model (lure carrier, payload, evasion vehicle) then organized what the extensions were actually for.
The six clusters:
- CarShield mass-blast ring. Auto-warranty lead-gen blasted from more than 30 sending domains, primarily carrying
.xlsxand.pdflures. Display names impersonate CarShield through unicode tricks, and filenames are date-encoded or hex-randomized. - PST-lure life-insurance ring. Serves
.pstOutlook archives as the lure attachment, rotating auto and life-insurance pitches over the same infrastructure. Filenames mimic account exports (Account_Statement.pst,User_Account_Details.pst). - Python-payload auto-insurance ring. Delivers
.pyand.pywscripts under insurance-quote subjects. A Python script arriving in consumer email is essentially never legitimate, so these are payload-delivery attempts. - The
.wordssingle-day burst. On 2026-04-25, a throwaway domain fired 13 distinctalibaba-prefixed senders in one day, each attaching a.wordsfile named after the recipient's own username. The.wordsextension is not produced by any consumer software. - cal.com ICS crypto-recovery abuse. Legitimate cal.com calendar invites whose meeting titles carry fabricated support personas and dollar or BTC amounts, with a Telegraph page as the landing.
- The
.orderApple-order dropship. A single purpose-built merchant domain sendingApple_Order_Tracking_<N>.ordershipping-notice pretexts through an ESP-styled tracking domain.
Two clusters were still emerging in the window. Seven sender domains delivered Apple Wallet .pkpass passes as scam attachments, a persistence channel rarely documented in attachment-threat literature. A separate set delivered voicemail.mp3 files paired with a "missed call from your insurer" subject line and a callback number.
The sending infrastructure splits along a clear line. A small set of domains is operator-built and disposable. The larger set is compromised: aged, real small-business and community domains whose mail was hijacked to relay the blasts. The table below separates them by role, defanged.
| Indicator | Role | Notes |
|---|---|---|
hbkcgy[.]com |
Send + landing | Operator-built throwaway; 13-sender single-day .words burst plus a PHP redirector |
as-notify8[.]com |
Tracking / redirect | Purpose-built (reg 2024-11), ESP-styled numeric routing subdomains, no real ESP footprint |
eviseren[.]com |
Sender | Purpose-built dropship merchant (reg 2025-05); Apple-order .order pretext |
shawandboehler[.]com |
Sender | Lapsed and re-registered expired domain; .json-as-attachment evasion |
baybridgeservices[.]com |
Redirect | Aged domain, mail/hosting hijacked; homoglyph PHP redirect layer |
tez-group[.]com |
Sender | Aged real web-agency domain, hijacked as a .json evasion relay |
| 30+ aged SMB / community domains | Sender | Compromised legitimate small-business sites rotated as throwaway relays |
How It Works
A representative CarShield contact chain looks like this. The recipient gets a message whose display name reads as some corrupted form of the CarShield brand, from a compromised small-business domain that passes authentication because the operator re-armed it with strict DMARC. The body says almost nothing. The attachment, a date-named spreadsheet, renders a fake auto-warranty quote with a button to click or a number to call. There is no link in the message for a URL scanner to score, because the link is drawn inside the spreadsheet.
The PST ring works the same way at the delivery layer but escalates the payload. The attachment is an Outlook archive, and opening it loads attacker-controlled mail state rather than showing a document. The Python ring goes further still: the attachment is a script, and running it is direct compromise.
The evasion-vehicle clusters hide the link one level down. The .order dropship sends a shipping-notice pretext whose tracking button resolves through a purpose-built redirect domain. The cal.com cluster hides its Telegraph landing page inside a calendar invite's meeting description, so the malicious content rides in on a legitimate scheduling platform's authenticated mail.
Sample Lures
The samples below are attacker-side content only. Recipient identifiers have been removed and replaced with placeholders, and every domain and URL is defanged.
CarShield auto-warranty spreadsheet lure:
From: "CarShield~Coverage" <fastrates_@core.milanflightgear[.]com>
Subject: RE: // 2026 AUTO PROTECTION QUOTES
Attachment: March.09,2026 .xlsx
Body: (near-empty; quote and click target rendered inside the spreadsheet)
PST life-insurance lure:
From: "New York Life Coverage" <postmaster@jessbronk[.]com>
Subject: New York Life Coverage update
Attachment: April2026.pst
Apple-order dropship .order pretext:
From: <info@eviseren[.]com>
Subject: Your order 60189 is on its way
Attachment: Apple_Order_Tracking_60189.order
Tracking CTA host: url2220.as-notify8[.]com
cal.com calendar-invite crypto-recovery lure (operator strings injected into the meeting title):
From: <hello@cal.com>
Attachment: event.ics
Meeting title: CRYPTO NOTICE 566453 Mary from CRYPTO MIN support
Body pattern: Confirmed: 30min with <operator-meeting-title> at <time>
Landing: telegra[.]ph
Voicemail callback lure (the audio file is inert; the funnel is the phone number in the subject):
From: <voicemail sender, life-insurance pretext>
Subject: New Voicemail Transcription from (844) 722-2197
Attachment: voicemail.mp3
The .words single-day burst:
From: alibaba-<random>@hbkcgy[.]com
Subject: [25|April] cheap rates!
Attachment: [recipient username].words
Technical Analysis
Three Functional Roles, One Design Choice
The extension is not the useful unit of analysis. The intent is. The same .pdf can be an HSBC payment-receipt impersonation or an Apple-Pay-charge-failure pretext, but in both it is a lure carrier that never executes. A .py, .pst, or .ppam, by contrast, is payload-class regardless of the subject line. Sorting the roughly 21 observed extensions into three roles captures what the operator wants the recipient to do on open.
| Role | What the operator wants on open | Representative extensions |
|---|---|---|
| Lure carrier | Click an in-file button, call a number, or scan a QR code; the file itself is inert | .pdf .xlsx .docx .png .jpg .heic .txt .mp3 .mp4 .pptx |
| Payload / executable | Code, macro, or archive runs or loads, meaning compromise | .py .pyw .ppam .xlsm .mso .pst (and some .zip) |
| Evasion vehicle | A link or instruction hides inside a filter-bypassing container | .html .htm .ics .words .order .json .vcf .pkpass |
The single design choice unifying all three roles is body-CTA absence. The click target, the callback number, or the executable is moved out of the message body and into the file, so a body-URL scanner and a body-text classifier both see nothing actionable. This structural property is what unifies six otherwise-unrelated operators. It is not a shared host or a shared registrar that binds them.
Novel and Non-Consumer Extensions
Several operators reach for extensions no legitimate consumer software emits, which lets them evade blocklists tuned for the obvious dangerous types. The choice is deliberate and it maps cleanly to intent.
| Extension | Class | Operator intent |
|---|---|---|
.words |
Evasion (novel) | No consumer software emits it; basename is the recipient's own username |
.order |
Evasion (novel) | Mimics an Apple shipping notice (Apple_Order_Tracking_<N>.order) |
.json |
Evasion (novel) | Not a consumer artifact; sent from aged, DMARC-re-armed domains |
.vcf |
Evasion (novel) | Contact card carrying a URL in an embedded field (lottery pretext) |
.pkpass |
Evasion / persist | Signed Wallet pass; back-of-pass callback or URL; survives deletion |
.pst |
Payload | Outlook-archive load; account-export filenames |
.py / .pyw |
Payload | Script to RAT or stealer; never legitimate in consumer email |
voicemail.mp3 |
Lure (audio) | Inert audio; the callback number lives in the subject line |
Filename Grammar
Operators treat the filename as both lure and evasion signal. Date-encoded names (March.09,2026 .xlsx, April2026.pst) imply freshness and pressure a fast open. Recipient-personalized names ([username].words, [borrower name]_ROV_Disclosure.pdf) imply the file is meant for that person specifically. Brand-mimicking names (Apple_Order_Tracking_<N>.order, HSBC_MoneyTransfer_Receipt.pdf) do the impersonation work before the file even opens. Hex-randomized names (08495449.pdf) defeat filename-based dedupe. And a counter-incrementing pattern, Statement1_from_My_Family_Trust_LLC1.pdf through Statement17_..._17.pdf, is a clean operator fingerprint for systematic advance-fee blasts.
Unicode and separator garble appears on both filenames and subjects to bypass keyword rules: Crus&hRa-tes!.pdf, (Introduc#ing)C:@RSshI#eleD.xlsx, and subject-line separators such as |, *, and arrow glyphs.
Sender Grammar and Display-Name Rotation
The sender addresses carry their own conventions. Role-word prefixes front operator apexes (core.milanflightgear[.]com, panel.vapdts[.]com), and the tracking apex uses incrementing numeric routing subdomains (url2220., url4469.as-notify8[.]com) to look like an email service provider. Local parts advertise the pretext directly: fiidelity@, fast_rates@, insurance_savings_co-@, emily-from-carshield@.
Display-name rotation is where the CarShield vertical shows its scale. Across the window it cycled 1,110 distinct display-name variants that all resolve to the CarShield brand. The rotation mechanisms include case-shuffling (cArSHiELD), separator and ligature injection (Car|shield, car[shielD]), zero-width and invisible characters padding the string, leading emoji and symbol glyphs, wrapper characters (*carshield*, +CarShield+), and homoglyph corruption of the brand token itself (carrshield). Exact-string brand matching has no chance against a thousand spellings of one word.
Registration Cohorts
Public WHOIS sorts the operator and relay domains into two clean cohorts. Creation date, not our first-seen data, is the reliable signal here.
| Domain | Registrar | Created | Cohort |
|---|---|---|---|
shawandboehler[.]com |
Dynadot | 2004-10-22 | Aged, re-armed (florist defunct, domain re-registered) |
baybridgeservices[.]com |
Wild West Domains | 2014-04-23 | Aged, hijacked (redirect layer) |
tez-group[.]com |
GoDaddy | 2014-09-08 | Aged, hijacked (.json evasion relay) |
hbkcgy[.]com |
Dynadot | 2018-01-30 | Aged throwaway (.words burst) |
as-notify8[.]com |
Cloudflare | 2024-11-21 | Purpose-built (tracking / redirect) |
eviseren[.]com |
Tucows | 2025-05-17 | Purpose-built (dropship merchant) |
The aged cohort shares a fingerprint worth flagging: the .json evasion senders and the redirect layer all publish self-configured DMARC p=reject. Old apexes were re-armed with strict authentication so the blasts pass alignment checks, which is the opposite of what a dormant or abandoned domain looks like.
Escalation and Change
Two behaviors show the operators adapting. The .words cluster began as a single-apex, single-day burst, then migrated wholesale onto a rotating pool of roughly 30 compromised small-business domains, which makes any block on the original apex obsolete. The Python-payload ring migrated the same way onto its own compromised pool. Rotation at the domain layer is the point: no single sending domain is the durable indicator, so a defender who blocks domains is always a step behind. The .pkpass and voicemail.mp3 clusters, meanwhile, are net-new format experiments, one adding on-device persistence and the other defeating both URL-reputation and content scoring by carrying no link and no payload at all.
Detection Observations
The behavioral signal that separates this traffic from legitimate mail is structural. It does not depend on the words in the body. A message that carries an attachment and offers no body-level click target is the shape shared across every cluster here. When a flagged email has an attachment and no URL anywhere in the body, the click target is inside the file, and that combination is detectable as a feature without parsing the attachment at all.
Some clusters carry strong per-message signal on top of that. Payload-class extensions in consumer email (.py, .pyw, .pst, .ppam) are almost never legitimate, so their mere presence is close to decisive. Novel extensions that no consumer software produces (.words, .order, .json-as-attachment, .vcf) behave the same way, which argues for treating "extension never emitted by legitimate consumer software" as a single class rather than chasing each new suffix individually.
The harder cases are the lure carriers, because a scam .pdf or .xlsx shares a file type with enormous volumes of legitimate transactional and personal mail. There, the signal lives in the combination: a brand-impersonating display name with a thousand unicode spellings, a date-encoded or recipient-personalized filename, and an empty body. Single-day bursts also read differently depending on the window: a coordinated one-day blast blends into a 90-day aggregate rollup, yet stands out sharply on a same-day sender fingerprint, so the burst is easier to characterize at day resolution than in the long-window view.
MITRE Fight Fraud Framework Mapping
The mapping aligns to the MITRE Fight Fraud Framework (F3). Technique IDs from that matrix are omitted where a precise identifier could not be confirmed; the tactic and technique names below use the Fraud-matrix vocabulary.
| Tactic | Observed behavior | How it appeared here |
|---|---|---|
| Resource Development | Acquire and re-arm infrastructure | Purpose-built throwaway domains plus aged domains re-registered or hijacked and re-armed with strict DMARC |
| Initial Access | Phishing message with attachment | Auto-warranty, insurance, shipping, and voicemail pretexts delivered as attachment-bearing email |
| Stealth | Evade content and link inspection | Malicious link, callback, or code moved into the attachment so the body offers nothing to score |
| Initial Access | Brand and platform impersonation | CarShield, insurer, bank, and Apple pretexts; abuse of authenticated cal.com and Wallet infrastructure |
| Execution | Drive a call, click, or execution | In-file buttons, callback numbers, QR codes, and executable payloads |
| Monetization | Lead-gen sale, advance-fee, dropship, credential or malware access | Insurance lead capture, inheritance blasts, dropship fraud, and payload-borne account theft |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. Domains that resolve to legitimate businesses or platforms (for example the impersonated insurer's own domain) are deliberately excluded. Sending domains marked as compromised relays are hijacked legitimate small-business sites, not operator-owned infrastructure.
Senders
| Value | Role | Notes |
|---|---|---|
info@eviseren[.]com |
Sender | Apple-order .order dropship (operator-built) |
alibaba-<random>@hbkcgy[.]com |
Sender | .words single-day burst, 13 addresses (operator-built) |
life_insurance_team@panel.vapdts[.]com |
Sender | Life-insurance lead-gen |
fiidelity@anokana[.]com |
Sender | Python-payload ring |
fast_rates@pakoloren[.]com |
Sender | Insurance lead-gen (CIC-impersonation filename pretext) |
insurance_savings_co-@utilometro[.]com |
Sender | Insurance lead-gen |
emily-from-carshield@advancedlogic4u[.]com |
Sender | CarShield impersonation |
postmaster@ocean-vistas[.]com |
Sender | PST-lure ring (compromised relay) |
postmaster@dralancohn[.]com |
Sender | PST-lure ring (compromised relay) |
*fast_insurance_rates*@handsimulatorgame[.]com |
Sender | CarShield ring / .ppam carrier (compromised relay) |
… (representative subset; dozens of verified-malicious sending addresses)
Domains
| Value | Role | Notes |
|---|---|---|
hbkcgy[.]com |
Send + landing | .words burst infra (operator-built throwaway) |
as-notify8[.]com |
Tracking / redirect | Dropship .order routing (purpose-built) |
eviseren[.]com |
Sender | Apple-order dropship merchant (purpose-built) |
shawandboehler[.]com |
Sender | .json evasion; lapsed and re-registered expired domain |
tez-group[.]com |
Sender | .json evasion (compromised aged web-agency domain) |
baybridgeservices[.]com |
Redirect | Homoglyph PHP redirector (compromised aged domain) |
panel.vapdts[.]com |
Sender | Life-insurance lead-gen sending subdomain |
core.milanflightgear[.]com |
Sender | CarShield ring sending subdomain (compromised relay) |
anokana[.]com |
Sender | Python-payload ring |
tracyscustomboatcovers[.]com |
Sender | CarShield ring (compromised SMB relay) |
… (representative subset; 50+ verified-malicious sending and relay domains)
Hosts
| Value | Role | Notes |
|---|---|---|
url2220.as-notify8[.]com |
Tracking | Dropship .order CTA host |
url4469.as-notify8[.]com |
Tracking | Dropship .order routing host |
r3828.baybridgeservices[.]com |
Redirect | Homoglyph PHP redirect host (on a compromised domain) |
URLs
| Value | Role | Notes |
|---|---|---|
http[:]//url2220.as-notify8[.]com/ |
CTA | Dropship .order tracking |
http[:]//r3828.baybridgeservices[.]com/r3828.php?32= |
Redirect | Homoglyph redirector |
Conclusion
The attachment is now a first-class delivery vector, competing directly with the inline-URL channel that most email defenses were built to read. The operators here are not sophisticated in any single technique; their edge is the shared insight that a scanner reading the body and scoring the links sees nothing when the link lives one layer down. Defenders should watch the structural shape rather than the domains: an attachment with no body-level click target, a payload-class or novel extension, and a brand-impersonating display name that refuses to spell the brand the same way twice. The domains will keep rotating. The shape will not.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.