Callback phishing via Google Group abuse

A fraudulent invoice/receipt found in the body of the message, delivered via a Google Group mailing list.

Sublime rule (View on GitHub)

 1name: "Callback phishing via Google Group abuse"
 2description: "A fraudulent invoice/receipt found in the body of the message, delivered via a Google Group mailing list."
 3type: "rule"
 4severity: "high"
 5source: |
 6  type.inbound
 7  and length(attachments) < 5
 8  and sender.email.domain.domain == "googlegroups.com"
 9  and (
10    any(attachments,
11        (.file_type in $file_types_images or .file_type == "pdf")
12        and (
13          any(file.explode(.),
14              // exclude images taken with mobile cameras and screenshots from android
15              not any(.scan.exiftool.fields,
16                      (
17                        .key == "Model"
18                        or (
19                          .key == "Software"
20                          and strings.starts_with(.value, "Android")
21                        )
22                      )
23                      // exclude images taken with mobile cameras and screenshots from Apple
24                      and (
25                        .key == "DeviceManufacturer"
26                        and .value == "Apple Computer Inc."
27                      )
28              )
29              and any(ml.nlu_classifier(.scan.ocr.raw).intents,
30                      .name == "callback_scam" and .confidence == "high"
31              )
32          )
33        )
34    )
35    or any(ml.nlu_classifier(body.current_thread.text).intents,
36           .name in ("callback_scam") and .confidence == "high"
37    )
38  )
39  
40  // negate highly trusted sender domains unless they fail DMARC authentication
41  and not (
42    sender.email.domain.root_domain in $high_trust_sender_root_domains
43    and coalesce(headers.auth_summary.dmarc.pass, false)
44  )  
45
46attack_types:
47  - "Callback Phishing"
48tactics_and_techniques:
49  - "Free email provider"
50  - "Impersonation: Brand"
51  - "Social engineering"
52detection_methods:
53  - "File analysis"
54  - "Natural Language Understanding"
55  - "Optical Character Recognition"
56  - "Sender analysis"
57id: "199d873b-9703-50df-a8d5-f4dc4322222b"
to-top