The reported Q3 2026 VBSpam test examined 103,969 emails over 16 days and found that phishing can arrive through authenticated infrastructure while browser side cloaking conceals the final destination. Campaigns used Amazon SES and a DKIM aligned domain, conditional redirects, hidden HTML elements, obfuscated JavaSc...
Published byEdited with GPT-5.6 TerraImages generated with GPT Image 2
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Virus Bulletin’s Q3 2026 VBSpam comparative test reveal about phishing campaigns that abuse authenticated email services and multi-. Article summary: Virus Bulletin’s Q3 2026 VBSpam test indicated that modern phishing often succeeds by combining legitimate, authenticated sending infrastructure with browser-side cloaking that hides the real destination from simple emai. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clic
Phishing defenses cannot treat a technically authenticated email as inherently trustworthy. Reporting on Virus Bulletin’s Q3 2026 VBSpam comparative test describes campaigns that combined apparently legitimate sending infrastructure with multi-stage, browser-aware URL cloaking—moving the malicious behavior beyond what a basic sender or static-link check can reveal. The test ran for 16 days under an AMTSO test plan and assessed 103,969 emails, including 103,380 spam messages. 1
3
SPF, DKIM and DMARC help validate aspects of a message’s sending path and domain alignment. They do not establish that an email’s content is benign, that every link is safe, or that the final page reached after a redirect chain is legitimate.
That distinction is central to the campaigns described in reporting on the test. Attackers used authenticated or trusted-looking infrastructure, then deferred the harmful action to a web flow that could inspect a visitor’s browser, location or timing before presenting a destination. 3
5
One German-language campaign used an overdue-payment theme and was sent through Amazon SES from a DKIM-aligned domain. Rather than relying on an attachment, the HTML email reportedly included decoy markup, hidden text, a zero-size iframe and obfuscated JavaScript. 3
5
The linked flow was designed to evaluate the visitor: it fingerprinted browser and timezone information, made a concealed POST request, and redirected qualifying visitors to OpenSea. That sequence was reported as consistent with cloaked cryptocurrency or NFT fraud, while making simple inspection of the initial message or URL less revealing. 3
5
A Dutch-language campaign impersonated McAfee and TotalAV, warning recipients about “631 dangerous viruses” and promoting a discounted renewal. The lure used HTML-only social engineering rather than a conventional malicious attachment. 3
5
Its key evasive property was conditional delivery: the destination could change according to time, location or the apparent victim profile. This makes automated scanning harder because a scanner may receive a harmless page, an error, or a different redirect path from the one shown to a targeted recipient. The reported objective was subscription fraud. 3
5
A Romanian-language phishing message impersonated BCR S.A. and claimed that PSD2 consent required renewal. Reporting on the campaign says the destination was obscured with an IPv6-mapped address, an obfuscation technique that can complicate URL parsing and scanner analysis. 3
The apparent theme—mandatory banking-consent renewal—is suited to credential theft because it pressures a recipient to act quickly in a familiar financial workflow. 3
These examples point to a shift in where phishing logic lives. The initial email may contain a sender that passes authentication and a link whose intent is not immediately obvious. The decisive behavior occurs later, in the browser:
For defenders, the implication is not to discard email authentication. It is to treat authentication as one input within a broader assessment of message content, sender reputation, link behavior and destination risk. 3
5
A stronger email-security workflow needs to inspect the full path, not just the first signal:
The reported composite results suggest that very high overall detection was achievable among the strongest products, but performance was not uniform. Net at Work NoSpamProxy recorded a 99.995 final score with no false positives; Bitdefender GravityZone Premium scored 99.994; and SEPPmail.cloudfilter scored 99.985. Rspamd was reported at 62.5%. 3
5
Those figures should be read as results from this specific comparative test, not as a universal guarantee for any environment. Still, the gap reinforces the practical lesson: handling authenticated senders, obfuscated URLs and conditional browser flows requires layered inspection rather than dependence on a single control. 1
3
5
The Q3 2026 VBSpam reporting illustrates a phishing model built around a simple asymmetry: attackers can make the email look acceptable at delivery time, then reveal the fraud only after the recipient’s browser meets selected conditions. Sender authentication remains necessary infrastructure hygiene—but the security decision must extend through the full redirect chain and final web experience. 3
5
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
The reported Q3 2026 VBSpam test examined 103,969 emails over 16 days and found that phishing can arrive through authenticated infrastructure while browser side cloaking conceals the final destination.
The reported Q3 2026 VBSpam test examined 103,969 emails over 16 days and found that phishing can arrive through authenticated infrastructure while browser side cloaking conceals the final destination. Campaigns used Amazon SES and a DKIM aligned domain, conditional redirects, hidden HTML elements, obfuscated JavaScript and an IPv6 mapped address to obscure crypto/NFT, subscription and banking credential fraud paths.
Reported composite scores ranged from 99.995 for Net at Work NoSpamProxy, with no false positives, to 62.5% for Rspamd—evidence that outcomes varied sharply across tested products.