Security advisories

Findings from our own investigations, published with the indicators other defenders need to act on them.

Published

LH-2026-001 · Published 2026-08-06 · TLP:CLEAR
Credential-Phishing Campaign Distributed From a Compromised AirDroid (Sand Studio) Mailbox

Mail sent from a vendor's own business-development mailbox passed SPF, DKIM and DMARC under a p=reject policy. The operator replied in-thread when challenged. The payload is a two-stage adversary-in-the-middle kit — a Microsoft-branded gate on a hijacked domain handing the victim's address to a Cloudflare-fronted domain registered seven days earlier — using cloaking that defeats automated URL scanning. Full IOCs, hunting guidance and disclosure timeline included.

How to read these

Each advisory separates what we observed from what we inferred, states a confidence level per finding, and carries a section titled What we did not find. Where we could not establish something, we say so rather than rounding up.

Note on indicators

Indicator blocks may reference infrastructure that was live at time of publication. Treat every URL and domain in an advisory as hostile. Do not visit them from a workstation, and do not authenticate against them under any circumstances.

Machine-readable feeds

Indicators are published alongside each advisory in CSV and STIX 2.1 for direct ingestion:

AdvisoryCSVSTIX 2.1
LH-2026-001 lh-2026-001-iocs.csv lh-2026-001.stix.json

Reporting to us

To report a security issue in a Lifted Holdings product or service, see the vulnerability disclosure policy or email will@liftedholdings.com.