216.73.216.197

Spam Campaign Abuses Atlassian Jira, Targets Government and Corporate Entities

· Published 18/02/2026 12:11 · Modified 18/02/2026 16:40

Export JSON

Essential information

Published
18/02/2026 12:11
Modified
18/02/2026 16:40
Tags
2026-02-18 atlassian jira domain reputation email security keitaro tds phishing saas abuse spam campaign targeted attacks
Related entities
8 techniques (mitre), 5 others

Description

A sophisticated exploited Cloud to bypass security controls and target government and corporate entities. The attackers used legitimate Atlassian Cloud infrastructure to create disposable Jira instances, leveraging the platform's trusted . The campaign targeted specific language groups, including English, French, German, Italian, Portuguese, and Russian speakers, with tailored emails redirecting to investment scams and online casinos. The operation demonstrated high automation and abuse of SaaS workflows, highlighting the need for reassessing trust assumptions in cloud-generated emails. The campaign utilized Keitaro Traffic Distribution System for redirects and focused on organizations already using , exploiting their familiarity with Jira-related emails.

External references