Skip to content

Fake legal threats through your contact form: the malware lure

Fake copyright complaints sent through website contact forms have been used to deliver malware since at least 2021. How the lure works, how to spot one, and what to do instead of clicking.

Humainbox 10 min read
In this piece
  1. What the security researchers found
  2. Why a contact form makes the lure believable
  3. How to recognise the lure
  4. How genuine legal complaints usually arrive
  5. What to do with one
  6. Where it is hard
  7. Further reading

A typical message looks like this. It arrives in the same notification format as every other enquiry from your website:

Hello,

Your website is using images that I own without my permission. This is copyright infringement and you could be sued for damages. I have collected the evidence, including the images and where they appear on your site. Download it here and check for yourself: [link]

If the images are not removed, I will take legal action.

It is not badly written, it does not sell anything, and it is frightening in a specific way: it suggests you have done something wrong and that a lawyer is involved. The link, in the campaigns security researchers have documented, leads to malware.

What the security researchers found

Microsoft, April 2021. Microsoft Threat Intelligence published "Investigating a unique 'form' of email delivery for IcedID malware", describing "activity where contact forms published on websites are abused to deliver malicious links to enterprises using emails with fake legal threats." The messages claimed the recipients had "used their images or illustrations without their consent, and that legal action will be taken against them", with phrases such as "you could be sued."

The link went to a sites.google.com page that required the recipient to sign in with a Google account, after which it "automatically downloads a malicious ZIP file". The script inside fetched IcedID, which Microsoft describes as "a banking trojan that has evolved to become an entry point for more sophisticated threats, including human-operated ransomware." Microsoft also noted the attackers "may have used a tool that automates this process while circumventing CAPTCHA protections."

Proofpoint, February 2024. The technique did not go away. In "Latrodectus: This Spider Bytes Like Ice", Proofpoint and Team Cymru describe a group tracked as TA578 that "typically uses contact forms to initiate a conversation with a target." On 20 February 2024 it was seen "impersonating various companies to send legal threats about alleged copyright infringement." The links led to a landing page "personalized to display both the target's domain and the name of the impersonated company", which then downloaded a JavaScript file from a Google Firebase URL. MITRE ATT&CK's entry for TA578 records that it has used contact forms and email to distribute Latrodectus, IcedID and Bumblebee.

The same theme by ordinary email. Copyright lures are not limited to contact forms. Check Point Research reported in November 2024 on emails from Gmail accounts claiming copyright violations, with download links that redirected "to Dropbox or Discord to download a password-protected archive (with the password provided in the email)", delivering the Rhadamanthys stealer. Trend Micro reported in March 2026 on "language-matched lures disguised as legal copyright violation notices", including German-language lures aimed at organisations in Germany.

A different lure, the same channel. In August 2025 Check Point described the ZipLine campaign, which started through targets' "Contact Us" forms. The attackers posed "as a potential business partner", asked for a non-disclosure agreement, and delivered a malicious ZIP file hosted on herokuapp.com, in some cases after up to two weeks of friendly correspondence.

Why a contact form makes the lure believable

When someone fills in your contact form, your website (or the email service it uses) sends the notification. The message arrives from your own infrastructure, in your own template, at the mailbox you set up to receive enquiries.

That matters in three ways.

The sender checks are checking you. Spam filtering on ordinary email leans heavily on who sent a message: the sending server's reputation, and whether authentication records such as SPF and DKIM line up. A form notification that is set up correctly usually passes those checks, because your site really did send it. The attacker's identity never reaches that layer. Microsoft put it this way: the email "appears trustworthy as it was sent from trusted email marketing systems." Check Point made a similar point about ZipLine: starting from a contact form helped the attackers avoid "reputation-based detection mechanisms." This is the same reason blocklists do not work on a contact form.

The format is one you trust. In Microsoft's words, "As the emails are originating from the recipient's own contact form on their website, the email templates match what they would expect from an actual customer interaction or inquiry."

The links point at real services. Google Sites, Firebase, Dropbox, Heroku. A link filter that trusts large, legitimate hosts has nothing to object to, and Microsoft noted that the sign-in step on the Google page meant "detection technologies may fail in identifying the email as malicious altogether."

How to recognise the lure

The documented messages share a shape. Any two of these together should stop you:

  • A legal consequence with a short deadline. Sued, damages, action within 24 or 48 hours, "download it right now".
  • Evidence you have to fetch. The proof is behind a link, not in the message. A genuine complaint about a photograph names the photograph and the page.
  • A file-hosting or site-hosting link. Google Sites, Firebase, Dropbox, Discord, a short URL. Real solicitors and rights holders do sometimes use file sharing, but they explain what the file is and who they are first.
  • A request to sign in, unzip or open a password-protected archive. A password in the same message as the link exists to stop scanners reading the file, not to protect you.
  • Personalisation that proves nothing. Proofpoint's landing pages displayed the target's own domain. Seeing your website's name on the page does not mean the sender knows anything about it.
  • No identifiable work. No image filename, no URL on your site, no registration or licence reference, no named client.

For how this fits alongside the ordinary sales spam arriving through the same form, see the contact form spam you get most.

It helps to know what the real thing contains, because it is quite different.

In the United States, a copyright takedown notice under section 512 of the DMCA is sent to a service provider's designated agent. The US Copyright Office advises: "Send your notice to the OSP's registered DMCA agent", and lists what a notice must include, among them "identification of the copyrighted work claimed to have been infringed", contact information for the copyright owner or agent, and a statement "under penalty of perjury" that the sender is authorised to act.

In England and Wales, the Practice Direction on Pre-Action Conduct expects a claimant to write first with "concise details of the claim", including "the basis on which the claim is made, a summary of the facts, what the claimant wants from the defendant, and if money, how the amount is calculated." The defendant is expected to respond within "14 days in a straightforward case".

Neither looks like a threat to sue within 48 hours unless you download a file. Other countries have their own rules, and if a complaint looks as though it might be real, confirm the position with your own legal adviser.

What to do with one

  1. Do not open the link or any attachment. Do not sign in to anything it leads to. The UK National Cyber Security Centre's advice is simple: "Don't click on any links in a suspicious email."
  2. Verify independently. If the message names a company or law firm, find its contact details yourself and ask whether it sent the complaint. If it names an image, check your own site and records for that image.
  3. Report the message. In the UK, forward it to [email protected]; the NCSC says it "will analyse the suspect email and any websites it links to" and may "work with hosting companies to remove links to malicious websites." In the US, the FTC asks people to forward phishing emails to [email protected] and report scams at ReportFraud.ftc.gov. In EU countries, the EU CSIRTs Network lists each member state's incident response team to contact.
  4. Report the link. Use the abuse reporting of the service hosting it, or report the page to Google Safe Browsing.
  5. If someone already clicked, tell whoever looks after your IT straight away, before anything else is opened on that machine.
  6. Brief whoever reads the form mail. Microsoft recommends "educating users about identifying social engineering attacks". In a small business the person reading website enquiries is often not the person who would ever receive a legal letter, which makes them a good target.

If your organisation has an IT provider, ask them to check mail rules too. Microsoft advised reviewing "mail flow rules to check for broad exceptions", such as domain-level allow-lists, "that may be letting these emails through". A rule that waves through anything from your own domain waves through your form notifications with it.

Lure Typical ask The tell Safe response
Stolen images or copyright Download the "evidence" Deadline, no image or page named Do not open; check your own site; report
DMCA or takedown notice Open a file or sign in Sent via your form, not a formal notice with the work identified Verify with the named rights holder directly
Data-protection complaint Download a "report" Threat of regulator action, file to open Treat any real request for personal data seriously; never via the link
Business partner or NDA Sign or open a shared document Friendly contact, then a ZIP Verify the company independently before opening

Where it is hard

Real legal correspondence does sometimes arrive through a contact form. A photographer who finds their image on your site may well use the only contact route on the page. A person asking what data you hold about them is entitled to: the UK Information Commissioner's Office says a subject access request can be made "verbally or in writing, including by social media", to "any part of your organisation."

So deleting everything with a legal tone is not safe either. The better rule is to route it: anything that mentions copyright, legal action or personal data goes to a named person who knows to verify it through an independent channel, and the links stay unopened until then. A genuine complainant can always tell you which work, which page and who they are, without a download.

Filtering can help, with limits. A reader that looks at the message rather than the sender can recognise the shape of the lure regardless of which address or service it came through. In Humainbox, a message held for that reason stays in the panel with its reason written out, and can be released if it turns out to be real; nothing is deleted. The how it works page covers how that works.

Further reading

Stop contact form spam

Change one setting in your contact form. Spam stops arriving, and real enquiries go to whoever should answer them. Try it for a week with nothing switched on.

We would like to count visits with Google Analytics, which sets two cookies. Decline and nothing is loaded and nothing is sent. What these are.