BEC/Fraud: Fake investment outreach from suspicious TLD
Detects unsolicited investment/funding outreach emails from suspicious TLDs. Targets mass-mailed spam campaigns offering business funding, capital allocation, and family office outreach.
Sublime rule (View on GitHub)
1name: "BEC/Fraud: Fake investment outreach from suspicious TLD"
2description: |
3 Detects unsolicited investment/funding outreach emails from suspicious TLDs.
4 Targets mass-mailed spam campaigns offering business funding, capital allocation,
5 and family office outreach.
6type: "rule"
7severity: "medium"
8source: |
9 type.inbound
10 // subject contains investment language
11 and (
12 strings.istarts_with(subject.base,
13 'financing for',
14 'investment into',
15 'an investment opportunity',
16 'investing in'
17 )
18 or any([subject.base, body.current_thread.text],
19 strings.icontains(., "family office")
20 )
21 )
22 // financial body content
23 and (
24 any(ml.nlu_classifier(body.current_thread.text).topics,
25 .name == "Financial Communications" and .confidence != "low"
26 )
27 or (
28 any(ml.nlu_classifier(body.current_thread.text).topics,
29 .name == "B2B Cold Outreach" and .confidence != "low"
30 )
31 and regex.icontains(body.current_thread.text,
32 'funding',
33 'capital',
34 '\d{3}k',
35 'rates from \d+%',
36 'funded in \d+',
37 'family office'
38 )
39 )
40 )
41 // suspicious sender
42 and (
43 sender.email.domain.tld in $suspicious_tlds
44 or sender.email.domain.tld in ("info", "de")
45 )
46tags:
47 - "Attack surface reduction"
48attack_types:
49 - "BEC/Fraud"
50tactics_and_techniques:
51 - "Social engineering"
52detection_methods:
53 - "Header analysis"
54 - "Sender analysis"
55 - "Content analysis"
56 - "Natural Language Understanding"
57id: "5d4c4a15-661c-5fd1-9d5f-1c72c8230be8"