DENTAL PHISH WATCH Technical analysis — for IT providers and security researchers DPW-2026-001-T

Technical analysis of the campaign

What we have established from message evidence and a victim-side incident, what we infer, and what we still need. Written for the IT providers and security people who look after dental practices. The plain-language advisory is at the main page; this page assumes technical background. Corrections and additional intelligence are welcome via the form below.

1Attack chain

ACCESSCompromise of a dental practice mailbox (both consumer Gmail and custom-domain business mailboxes observed)
DISTRIBUTIONShare-lure email sent from the genuine account to its correspondents, BCC to undisclosed recipients
DELIVERYFreshly registered .vu domain, short generic path, cloaked against scanners
EXECUTIONWindows payload; fake full-screen "Windows Update" overlay during install
OPERATIONInteractive hands-on-keyboard remote access; repeat visits weeks apart
PROPAGATIONVictim's address book becomes the next distribution list
Simulated fake Windows Update screen: black background, white text reading Working on updates 37% complete, Don't turn off your computer
Fig. T1 — Reconstruction of the fake "Windows Update" overlay reported during payload installation (black screen, white "Working on updates / Don't turn off your computer" text with a spinner). Simulated for awareness; the operator retains interactive control of the desktop behind it. Not a forensic capture.

The propagation model is what makes this campaign effective in a niche sector: every message arrives from a genuine, previously-corresponding address, so SPF, DKIM and DMARC all pass and reputation-based filtering is useless. Targeting requires no attacker knowledge of the industry — the compromised mailbox's own contact graph is the targeting.

2Message evidence

We hold original .eml files from three waves (12, 16 and 22 July 2026) plus a first-wave sample. Key observations from headers and bodies:

Authentication and origin

Lure construction

3Infrastructure

DOMAIN (defanged)PATHFIRST SEENSENDER TYPE
avernix[.]vu/accessearly waveconsumer Gmail
uvanv[.]vuearly wave
xornavo[.]vu/file12 Jul 2026business mailbox (custom domain)
lornica[.]vu/dental16 Jul 2026business mailbox (custom domain)
clientesetupdoc[.]vu/access22 Jul 2026consumer Gmail (decoy link in same mail)
docsecdental[.]vu/mesh22 Jul 2026consumer Gmail (payload link)

4Detection

Because domains rotate per wave, our open-source detector (browser extension, GitHub) scores message content rather than matching indicators alone. Signals, roughly in order of evasion-resistance:

  1. Share-lure phrasing with a link whose registrable domain is not a recognised file-sharing host (works on any TLD);
  2. The desktop/Windows-laptop instruction (operationally necessary to them — dropping it costs them victims);
  3. Brand mismatch: Microsoft/OneDrive branding with non-Microsoft link targets;
  4. High-risk TLD plus short generic path;
  5. Known-domain blocklist (zero-FP repeat detection only).

Server-side, the highest-leverage controls are a transport rule quarantining .vu/ links (we know of no legitimate .vu correspondence in Australian dentistry), an external-sender share-lure disclaimer rule, and resolver-level blocking of the .vu zone at practice routers. Copy-paste configurations for Microsoft 365 and Google Workspace are in the IT configuration guide.

For responders: on any suspected mailbox compromise, audit inbox rules before resetting anything else's passwords — observed BEC tradecraft generally, and hidden forward/move rules specifically, are how operators retain access and conceal replies after a password change fails to evict an authenticated session. Reset password, revoke sessions and app passwords, then check OAuth grants.

5Open questions — what we need from you

Original .eml samples (with headers) are available to legitimate researchers and responders on request via the form below. Please also report independently to the ACSC — our evidence is already lodged.

6Contact, ideas and intelligence

Ideas for the tooling, corrections to this analysis, intelligence to share, or anything else — this opens a pre-filled email in your own mail client, so you can attach files (.eml samples, hashes, logs) before sending. Reports of sightings should use the main reporting form instead.

Opens in your own mail application for review before sending. Don't include patient information.