BEC/Fraud: Penpal scam

This rule detects messages from individuals looking to establish contact under the guise of seeking friendship or a penpal relationship. Over time, they build trust and then exploit this relationship by asking for money, personal information, or involvement in suspicious activities.

Sublime rule (View on GitHub)

 1name: "BEC/Fraud: Penpal scam"
 2description: "This rule detects messages from individuals looking to establish contact under the guise of seeking friendship or a penpal relationship. Over time, they build trust and then exploit this relationship by asking for money, personal information, or involvement in suspicious activities."
 3type: "rule"
 4severity: "medium"
 5source: |
 6  type.inbound
 7
 8  // the sender or the reply-to is a freemail provider
 9  and (
10    sender.email.domain.domain in $free_email_providers
11    or (
12      not sender.email.domain.root_domain in $free_email_providers
13      and any(headers.reply_to,
14              .email.domain.root_domain in $free_email_providers
15      )
16    )
17  )
18  
19  // body contains pen ?pal
20  and regex.contains(body.current_thread.text, 'pen\s?pal')
21  
22  // and NLU Request
23  and any(ml.nlu_classifier(body.current_thread.text).entities,
24          .name == "request"
25  )
26  
27  // not a reply
28  and (length(headers.references) == 0 or headers.in_reply_to is null)
29  
30  // negate highly trusted sender domains unless they fail DMARC authentication
31  and not (
32    sender.email.domain.root_domain in $high_trust_sender_root_domains
33    and coalesce(headers.auth_summary.dmarc.pass, false)
34  )  
35attack_types:
36  - "BEC/Fraud"
37tactics_and_techniques:
38  - "Free email provider"
39  - "Social engineering"
40detection_methods:
41  - "Content analysis"
42  - "Header analysis"
43  - "Sender analysis"
44id: "a4bdfa17-7527-5ee2-a27b-44d03e190773"
to-top