Spear Phishing: A Real-World Example and a Deep Dive into the Rabbit Hole

JTS

Spear Phishing: A Real-World Example and a Deep Dive into the Rabbit Hole 🕳️🐇

Jeremy Silva 

Technology Leader | Technology Seer | Data Driven Professional | Human-AI Collaboration Expert

July 9, 2025

All company names, domain names, agencies and services have been hidden. If you are legitimate security researcher please message me and I’ll share my research notes.

Spear phishing is a targeted form of phishing where attackers craft emails specifically aimed at a person or group, often using topics of interest—like financial documents or recent events—to lure victims.

In this case, I received an email that appeared to come from a very real U.S. government organization. The signature looked legit, and the sender was a person easily found and verified through a quick Google search.


Subject: Dear Supplier,

The [REAL_AGENCY_HERE] invites you to review and respond to the attached Request for Quote (RFQ). Please go through the RFQ and submit your response before the specified due date. Kindly confirm receipt of this email to acknowledge your participation.

Best regards,


The email included a PDF attachment. Let me be crystal clear here:

Never. Ever. EVER blindly open a file attachment.

In my case, I played it safe and used an online PDF-to-JPG converter—again, never blindly open attachments. The form looked semi-professional and was dated just two days prior (7/7/25).

Article content
Fake RFQ Form from the PDF File.

The RFQ was requesting a Dell workstation with SKU 7680CTO311. A quick AI-powered search later, I found it matched a Dell Precision 7680, part of Dell’s “Configure to Order” (CTO) line—custom-built systems tailored for business needs. I couldn’t find an exact match for the SKU, but here’s the base model:

👉 Dell Precision 7680 Workstation (Also, yes, I do accept tips in the form of base $5,089 laptops.)


Next up: email headers.

Every email contains a header, which is like its passport through the internet—stamped by every server it touches. These headers help trace the origin and routing of the message.

Most phishing emails like this originate from servers in the Middle East, East Asia, or Eastern Europe. They’re usually non-traceable and difficult to shut down. But I like to run interesting ones through tools just to see what I can uncover.

And that’s when I went down a rabbit hole…


⚙️ [Warning: Nerdy Technical Section Ahead — Skip if You’re Allergic to Details]

  1. The phishing email appeared to originate from a compromised IP phone system (hosted at web.hackedserver.com). Pretty sure the server compromised.
  2. The attacker spoofed the sender using a fake email identity. In this case, the user was named vcom. (I’m leaving the name here in case any security researchers recognize it.)
  3. The fake email was accepted without any authentication by the main domain (hackedserver.com)—not a good sign.
  4. That main domain then delivered the email to my mail server. The originating server? A PBX system (an internet phone system). Someone’s VOIP system was compromised and blasting out phishing emails. (Reported.)
  5. The domain used for the fake website was hosted on Zoho.com, a legitimate email and marketing platform. That’s next-level sneaky. (Reported to them as well.)

🌎 Tracing the Attackers

The main delivery server was located in a data center in Dallas, run by what appeared to be a valid business with a LinkedIn presence. However, none of their websites were functioning. I attempted to report the abuse via their official abuse email address—it bounced. I eventually used alternative public contacts and finally got a read receipt.

Meanwhile, the attacker had registered their domain through Cosmotown.com, a legitimate registrar. And the website they used? Hosted at OVHcloud—notorious for turning a blind eye to abuse reports and frequently hosting malicious sites.


🎯 Final Thoughts & Observations

This was a well-coordinated phishing attempt:

  • They used separate services for web hosting and email delivery.
  • By avoiding shady email servers (like those from OVH), and using a legit platform like Zoho, they likely bypassed email filters.
  • Their email would’ve likely been caught by modern platforms like Gmail or Office 365. My older email server? Not so much.

If one of their hacked email sending servers goes down, they’ll just hack another and repeat. It’s a game of digital whack-a-mole.

Given the recent surge in fake LinkedIn accounts targeting defense industry employees, I wonder if these are the same actors—only now they’re stepping up their game. No more obvious Gmail accounts; now they’re using believable domains and government impersonations.

My rating? 3/10. They get points for using a real government contact and a legitimate platform, but lost major credibility with the underwhelming signature and a website still stuck on an “Under Construction” page. Very disappointing.

About the author

During his twenty-five professional years, Mr. Silva has had experience in nearly every facet of the Information Technology industry. Ranging from advanced data mining / data visualization systems to running multi-state small business IT infrastructures, Mr. Silva has always provided precise and cost-effective strategies to meet any client’s needs. With his tremendous work ethic and “Can-Do” attitude, Mr. Silva has always met every challenge head-on and with intelligent determination. Mr. Silva is also a certified NAUI Advanced/Nitrox Diver, hoping to get a few more wrecks under his belt in the Atlantic.