Credential phishing: Email delivery failure impersonation
Detects phishing emails impersonating email system notifications claiming delivery failures, rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality. These attacks typically claim incoming emails couldn't be delivered and direct users to malicious portals to harvest credentials.
Sublime rule (View on GitHub)
1name: "Credential phishing: Email delivery failure impersonation"
2description: |
3 Detects phishing emails impersonating email system notifications claiming delivery failures,
4 rejected messages, or email system issues requiring user action to 'fix' or 'recover' email functionality.
5 These attacks typically claim incoming emails couldn't be delivered and direct users to malicious
6 portals to harvest credentials.
7type: "rule"
8severity: "high"
9source: |
10 type.inbound
11 and (
12 any(ml.nlu_classifier(body.current_thread.text).intents,
13 .name == "cred_theft" and .confidence == "high"
14 )
15 or (
16 length(body.current_thread.text) < 250
17 and any(recipients.to,
18 strings.icontains(body.current_thread.text, .email.domain.sld)
19 or strings.icontains(body.current_thread.text, .email.local_part)
20 )
21 )
22 )
23 and (
24 regex.icontains(subject.subject, '(e)?mail(s)?')
25 or (
26 length(body.current_thread.text) < 700
27 and strings.ilike(body.current_thread.text, '*mail*')
28 )
29 or (length(subject.base) == 0 or subject.base is null)
30 )
31 and 3 of (
32 strings.ilike(body.current_thread.text, "*incoming messages*"),
33 strings.ilike(body.current_thread.text, "*server error*"),
34 strings.ilike(body.current_thread.text, "*blocked*"),
35 strings.ilike(body.current_thread.text, "*prevented*"),
36 strings.ilike(body.current_thread.text, "*notification*"),
37 strings.ilike(body.current_thread.text, "*fix email issues*"),
38 strings.ilike(body.current_thread.text, "*rejected*"),
39 strings.ilike(body.current_thread.text, "*recover and prevent*"),
40 strings.ilike(body.current_thread.text, "*failure*"),
41 strings.ilike(body.current_thread.text, "*rejection*"),
42 strings.ilike(body.current_thread.text, "*failed*"),
43 strings.ilike(body.current_thread.text, "*restore these messages*")
44 )
45 and (
46 any(body.links,
47 regex.icontains(.display_text,
48 "view",
49 "messages",
50 "recover",
51 "fix",
52 "portal",
53 "connect"
54 )
55 and not .display_text == "View Report"
56 and .href_url.domain.root_domain in ("gmass.co")
57 )
58 or (
59 length(body.links) < 3
60 and any(body.links,
61 any(recipients.to,
62 .email.domain.root_domain == ..display_url.domain.root_domain
63 and ..mismatched
64 )
65 )
66 )
67 or (all(recipients.to, .email.local_part == sender.display_name))
68 or any(body.links,
69 any(.href_url.rewrite.encoders, . == "proofpoint")
70 and .href_url.domain.root_domain not in $tranco_50k
71 and .href_url.domain.root_domain not in $org_domains
72 )
73 or any(recipients.to,
74 strings.icontains(sender.display_name,
75 strings.concat('MyReport For ', .email.local_part)
76 )
77 )
78 )
79 and not any(body.links,
80 regex.icontains(.display_text,
81 "view document",
82 "review (&|and) sign document"
83 )
84 )
85 and sender.email.domain.root_domain not in (
86 "bing.com",
87 "microsoft.com",
88 "microsoftonline.com",
89 "microsoftsupport.com",
90 "microsoft365.com",
91 "office.com",
92 "office365.com",
93 "onedrive.com",
94 "sharepointonline.com",
95 "yammer.com",
96 "ppops.net",
97 "opentext.com"
98 )
99
100 // negate org domains unless they fail DMARC authentication
101 and (
102 (
103 sender.email.domain.root_domain in $org_domains
104 and (
105 not headers.auth_summary.dmarc.pass
106 // MS emails from an org domain are router "internally" to MS, therefore, there is no authentication information
107 or not (
108 headers.auth_summary.dmarc.pass is null
109 and all(headers.domains,
110 .root_domain in ("outlook.com", "office365.com")
111 )
112 // typical emails from freemail Outlook accounts are from prod.outlook.com
113 and strings.ends_with(headers.message_id, "protection.outlook.com>")
114 )
115 )
116 )
117 or sender.email.domain.root_domain not in $org_domains
118 )
119
120 // negate highly trusted sender domains unless they fail DMARC authentication
121 and not (
122 sender.email.domain.root_domain in $high_trust_sender_root_domains
123 and coalesce(headers.auth_summary.dmarc.pass, false)
124 )
125 and not profile.by_sender().solicited
126 and not profile.by_sender().any_messages_benign
127
128attack_types:
129 - "Credential Phishing"
130tactics_and_techniques:
131 - "Impersonation: Brand"
132 - "Social engineering"
133detection_methods:
134 - "Content analysis"
135 - "Natural Language Understanding"
136 - "Sender analysis"
137id: "ee318b89-0d4e-5c94-80ad-08991d3958b2"