Blog

How Ray Cracked the Phish No Scanner Could Find

How Ray Cracked the Phish No Scanner Could Find

Alon Mazor

|

|

Reading Time:

5

min

glow

Table of Contents

Request a Demo

By submitting this form, you are agreeing to our Privacy Policy

Diagram: a clean Frame.io share link leads to a dead-end preview, while Ray downloads the original PDF via the Frame.io API and uncovers a hidden phishing link to a fake Microsoft 365 login on msauth[.]biz

TL;DR

  • A targeted credential phishing campaign delivered 22 emails to a single enterprise tenant within a two-hour window on August 27, 2026, engineered to pass every email gateway by hiding the payload behind legitimate Frame.io share notifications.

  • Static gateway scanners see a clean Frame.io link and give the email a safe verdict. They cannot read the shared asset inside the SaaS platform.

  • Just three minutes after the first email landed, a targeted employee reported it. But because the link led to genuine infrastructure, traditional security controls saw nothing malicious. Not until Ocean's agentic investigation engine, Ray, got inside the platform and pulled the true payload.

  • Operating like a human analyst at machine speed, Ray engineered a workaround to download the unclickable asset via Frame.io's GraphQL API, dissected its annotations, and exposed the AiTM infrastructure behind it.

The Perfect SaaS Share Delivery Trap

Attackers understand that a pristine sender reputation is the hardest operational asset to acquire. Instead of building one, the Phantom Preview campaign simply borrowed Frame.io's.

The lure itself was engineered to bypass human skepticism. The subject line read Jason Pitts shared "BTF Project" with you. A named sender and a plausible project title will make a message land in a creative team's inbox without a second thought. We observed this highly targeted credential theft campaign delivering exactly 22 emails to a single enterprise tenant within a two-hour window on August 27, 2026.

By using the platform's native notification system, the attacker triggered an email sent directly from notifications@frame[.]io. This attack was engineered so that every email gateway on the planet would pass it, and they did. It presented a legitimate sender and a legitimate infrastructure link. There was nothing anomalous to find, which is exactly why the agent layer matters.

Ray vs. the Invisible Payload

Security gateways evaluate email based on explicitly present content. When a static scanner encounters a SaaS share notification, it sees only the legitimate "View Project" button pointing to next.frame[.]io/share/.... It follows that link, lands on a clean Frame.io webpage, and stops.

There is a second layer to the Phantom Preview trap. The Frame.io preview was a dead end. The shared PDF renders in Frame.io's viewer as a flattened, non-clickable preview image. A static scanner parses HTML and DOM elements looking for clickable href tags, but it cannot click a visual representation of a button inside an image viewer. Even a sophisticated sandbox that securely renders the share page has nothing to act on and nowhere to follow. The front door is a solid wall.

Ray investigated the share and approached the dead end exactly as a determined human incident responder would.

A non-agentic scanner can only follow links that are present. When faced with an unclickable preview, Ray invented a path that was not offered to it.

Ray analyzed the context and reasoned that if the preview offered no way in, the malicious payload had to be embedded within the original file itself. The agent bypassed the visual interface entirely. Ray analyzed the platform architecture and reverse-engineered Frame.io's GraphQL GetAssetForDownload path.

Using this endpoint, Ray successfully retrieved the raw .pdf binary. The agent then cracked the file open and parsed its internal structure to hunt for embedded actions. By dissecting the document's /URI annotations (the metadata dictating where a click on the document's coordinates should lead), Ray exposed the true destination. Static scanners are structurally blind to this hidden payload.

The investigation did not stop at one message. Ray pivoted on the campaign's subject invariant, Jason Pitts shared "BTF Project" with you, to sweep the tenant's mail history, and found 21 identical siblings. That pivot is what turned a single suspicious share into a coordinated campaign.

Exposing the Adversary-in-the-Middle Chain

Extracting the hidden URL from the PDF allowed Ray to unmask the full multi-stage evasion sequence powering the Phantom Preview campaign.

  1. Email Lure: notifications@frame[.]io

  2. SaaS Host (link): next.frame[.]io/share/...

  3. Redirector (hidden in the PDF): byk48rlc...pages[.]dev

  4. Anti-Sandbox (301 redirect): Turnstile CAPTCHA

  5. Harvester (obfuscated JS): msauth[.]biz/Doc

Delivery sequence. The initial email and first hop are hosted on trusted platforms. The malicious URL is hidden behind the PDF inside Frame.io, while the final destination is shielded by a CAPTCHA and obfuscated JS.

The Anti-Analysis Layer

The PDF pointed to a Cloudflare Pages redirector, using a 35-character randomized subdomain (byk48rlcdi09lb092ik71gks40lzl051ltd.pages[.]dev). This redirected via a 301 to the newly registered domain msauth[.]biz (registered via eNom on August 6, 2026, and hosted on DigitalOcean at 167.99.178[.]222 behind Cloudflare). Crucially, at the time Ray unmasked it, msauth[.]biz had a 0/91 detection ratio on VirusTotal. It was completely clean to standard intelligence feeds.

The landing page did not immediately show the login prompt. To defend their pristine infrastructure from automated discovery, the attackers placed a Cloudflare Turnstile CAPTCHA in front of the page. This is a deliberate anti-analysis measure. Turnstile requires human-like interaction and validates complex browser fingerprints, causing traditional headless sandboxes and automated crawlers to time out or fail.

Only after passing the CAPTCHA did obfuscated JavaScript execute to reassemble a per-victim URL (e.g., ?s=gQpS40I). This tokenized URL design ensures analysts cannot easily share the link or replay the attack later. The malicious script only detonates if the session token matches the expected victim context. Once validated, it served the pixel-perfect Microsoft 365 clone at /common/oauth2/v2.0/authorize.

Block now

Ensure your network or proxy blocking includes the newly registered domain msauth[.]biz and its subdomains, which act as the final destination for the stolen credentials.

Defending the SaaS Trust Gap

Legitimate SaaS share notifications (Frame.io, Dropbox, DocuSign) are a massive abuse vector. You cannot verdict these solely on delivery signals or the first hop. If the delivery signal verdict and the asset verdict disagree, trust the asset. You must implement tooling that natively inspects the shared payload itself.

Detection pattern: Hunt for SaaS share notifications where the shared asset is a PDF containing an outbound /URI annotation that points off the SaaS platform, especially to a freshly registered domain or a *.pages[.]dev / *.workers[.]dev host. The share is trusted; the annotation inside the asset is the tell.

Indicator

Type

Role

Priority

msauth[.]biz

domain

Phantom Preview campaign invariant (AiTM destination)

High

167.99.178[.]222

ip

Phantom Preview campaign invariant (DigitalOcean hosting IP)

Medium

office.msauth[.]biz

domain

Phantom Preview campaign invariant (AiTM redirect)

High

/common/oauth2/v2.0/authorize

path

Phantom Preview campaign invariant (AiTM harvester path)

High

byk48rlcdi09lb092ik71gks40lzl051ltd.pages[.]dev

domain

Observed redirector (randomized subdomain, likely disposable)

Medium

notifications@frame[.]io

email

Provider infrastructure (do-not-block)

n/a

Static scanners stop at the email. Ray investigates like a relentless human analyst, pulling down assets and walking chains to find the truth at machine scale and speed. Attackers weaponize the transactional infrastructure of trusted SaaS platforms, making traditional blocklists and reputation checks fall short. Agentic investigation is the only way to expose what is hiding behind the share.

Frequently Asked Questions

Is Frame.io compromised?

No. The platform did exactly what it is designed to do, which is the whole point. The attackers weaponized the trust in Frame.io's legitimate notification infrastructure to bypass email gateways.

Would our gateway have caught this?

No. Static gateways only scan explicitly presented content. Because the delivery email contained a pristine link to a legitimate SaaS platform, there were no anomalous indicators for a gateway to detect.

How do we hunt for this in our own tenant?

Look for anomalies in SaaS share subjects (like unexpected projects or naming conventions) and hunt for outbound /URI annotations within shared PDFs, especially those pointing to newly registered domains or disposable redirectors.

We only found this one because something went looking.

Ray runs this investigation on every email, including the ones from senders your team already trusts. If a share notification like this is sitting in a mailbox somewhere in your tenant right now, we can tell you today.

See what Ray finds in your inbox →