Credential phishing: Email delivery failure impersonation

Detects phishing emails impersonating email system notifications claiming delivery failures, rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality. These attacks typically claim incoming emails couldn't be delivered and direct users to malicious portals to harvest credentials.

Sublime rule (View on GitHub)

  1name: "Credential phishing: Email delivery failure impersonation"
  2description: |
  3  Detects phishing emails impersonating email system notifications claiming delivery failures, 
  4  rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality.
  5  These attacks typically claim incoming emails couldn't be delivered and direct users to malicious 
  6  portals to harvest credentials.  
  7type: "rule"
  8severity: "high"
  9source: |
 10  type.inbound
 11  and (
 12    any(ml.nlu_classifier(body.current_thread.text).intents,
 13        .name == "cred_theft" and .confidence == "high"
 14    )
 15    or (
 16      length(body.current_thread.text) < 250
 17      and any(recipients.to,
 18              strings.icontains(body.current_thread.text, .email.domain.sld)
 19              or strings.icontains(body.current_thread.text, .email.local_part)
 20      )
 21    )
 22  )
 23  and (
 24    regex.icontains(subject.subject, '(e)?mail(s)?')
 25    or (
 26      length(body.current_thread.text) < 700
 27      and strings.ilike(body.current_thread.text, '*mail*')
 28    )
 29    or (length(subject.base) == 0 or subject.base is null)
 30  )
 31  and 3 of (
 32    strings.ilike(body.current_thread.text, "*incoming messages*"),
 33    strings.ilike(body.current_thread.text, "*server error*"),
 34    strings.ilike(body.current_thread.text, "*blocked*"),
 35    strings.ilike(body.current_thread.text, "*prevented*"),
 36    strings.ilike(body.current_thread.text, "*notification*"),
 37    strings.ilike(body.current_thread.text, "*fix email issues*"),
 38    strings.ilike(body.current_thread.text, "*rejected*"),
 39    strings.ilike(body.current_thread.text, "*recover and prevent*"),
 40    strings.ilike(body.current_thread.text, "*failure*"),
 41    strings.ilike(body.current_thread.text, "*rejection*"),
 42    strings.ilike(body.current_thread.text, "*failed*"),
 43    strings.ilike(body.current_thread.text, "*restore these messages*")
 44  )
 45  and (
 46    any(body.links,
 47        regex.icontains(.display_text,
 48                        "view",
 49                        "messages",
 50                        "recover",
 51                        "fix",
 52                        "portal",
 53                        "connect"
 54        )
 55        and not .display_text == "View Report"
 56        and .href_url.domain.root_domain in ("gmass.co")
 57    )
 58    or (
 59      length(body.links) < 3
 60      and any(body.links,
 61              any(recipients.to,
 62                  .email.domain.root_domain == ..display_url.domain.root_domain
 63                  and ..mismatched
 64              )
 65      )
 66    )
 67    or (all(recipients.to, .email.local_part == sender.display_name))
 68    or any(body.links,
 69           any(.href_url.rewrite.encoders, . == "proofpoint")
 70           and .href_url.domain.root_domain not in $tranco_50k
 71           and .href_url.domain.root_domain not in $org_domains
 72    )
 73    or any(recipients.to,
 74           strings.icontains(sender.display_name,
 75                             strings.concat('MyReport For ', .email.local_part)
 76           )
 77    )
 78  )
 79  and not any(body.links,
 80              regex.icontains(.display_text,
 81                              "view document",
 82                              "review (&|and) sign document"
 83              )
 84  )
 85  and sender.email.domain.root_domain not in (
 86    "bing.com",
 87    "microsoft.com",
 88    "microsoftonline.com",
 89    "microsoftsupport.com",
 90    "microsoft365.com",
 91    "office.com",
 92    "office365.com",
 93    "onedrive.com",
 94    "sharepointonline.com",
 95    "yammer.com",
 96    "ppops.net",
 97    "opentext.com"
 98  )
 99  
100  // negate org domains unless they fail DMARC authentication
101  and (
102    (
103      sender.email.domain.root_domain in $org_domains
104      and (
105        not headers.auth_summary.dmarc.pass
106        // MS  emails from an org domain are router "internally" to MS, therefore, there is no authentication information
107        or not (
108          headers.auth_summary.dmarc.pass is null
109          and all(headers.domains,
110                  .root_domain in ("outlook.com", "office365.com")
111          )
112          // typical emails from freemail Outlook accounts are from prod.outlook.com
113          and strings.ends_with(headers.message_id, "protection.outlook.com>")
114        )
115      )
116    )
117    or sender.email.domain.root_domain not in $org_domains
118  )
119  
120  // negate highly trusted sender domains unless they fail DMARC authentication
121  and not (
122    sender.email.domain.root_domain in $high_trust_sender_root_domains
123    and coalesce(headers.auth_summary.dmarc.pass, false)
124  )
125  and not profile.by_sender().solicited
126  and not profile.by_sender().any_messages_benign
127    
128attack_types:
129  - "Credential Phishing"
130tactics_and_techniques:
131  - "Impersonation: Brand"
132  - "Social engineering"
133detection_methods:
134  - "Content analysis"
135  - "Natural Language Understanding"
136  - "Sender analysis"
137id: "ee318b89-0d4e-5c94-80ad-08991d3958b2"
to-top