6.1 Email Attack Vectors: Phishing, Spear Phishing, BEC, and Spoofing
Key Takeaways
Email threat vectors follow an operational continuum from untargeted mass spam to hyper-targeted spear phishing and executive whaling campaigns engineered from open-source intelligence.
Business Email Compromise (BEC) relies primarily on social engineering and authority deception rather than malware, manifesting in CEO fraud, vendor invoice manipulation, payroll diversion, and attorney impersonation.
Email spoofing exploits SMTP's lack of native sender verification through display name deception, exact domain forging, lookalike typosquatting, and deceptive cousin domains.
Adversary-in-the-Middle (AitM) reverse proxy phishing frameworks (such as Evilginx2) bypass conventional multi-factor authentication by proxying authentication in real time and stealing post-auth session cookies.
Adversaries may evade gateway inspection through password-protected archives and abuse LNK or container workflows; ISO/VHD Mark-of-the-Web bypasses are chiefly a legacy or unpatched-Windows concern.
Email Attack Vectors: Phishing, Spear Phishing, BEC, and Spoofing
Email remains the predominant initial access vector across cybercrime and Advanced Persistent Threat (APT) campaigns. Because Simple Mail Transfer Protocol (SMTP, RFC 5321) lacks native identity verification, adversaries exploit structural trust to deceive users. Mastering email incident response requires understanding threat taxonomy, Business Email Compromise (BEC), technical spoofing, reverse proxy credential harvesting, and containerized attachments.
Email Threat Taxonomy: From Mass Spam to Executive Whaling
Adversarial email operations span an operational continuum from automated bulk delivery to bespoke social engineering:
- Spam: Unsolicited bulk email distributed indiscriminately. Malicious spam (malspam) delivers commodity trojans, botnet loaders, or generic scam solicitations, relying on volume over customization and making it detectable through Bayesian filters and IP reputation blocklists.
- Phishing (Bulk/Deceptive): Broad social engineering mimicking trusted consumer brands, cloud providers, or financial institutions (e.g., fake banking alerts or shipping notifications). The goal is mass credential harvesting or malware deployment across general employee populations.
- Spear Phishing: Targeted attacks directed at specific individuals, roles, or organizations. Attackers conduct Open Source Intelligence (OSINT) across professional networks and corporate websites, leveraging internal project names, vendor relationships, and organizational hierarchies to craft high-credibility pretexts.
- Whaling: A high-stakes subset of spear phishing targeting C-suite executives, board members, and finance directors. Pretexts exploit urgent emergencies—such as confidential mergers and acquisitions (M&A), regulatory investigations, or subpoenas—coercing victims into approving wire transfers or executive data disclosures.
Business Email Compromise (BEC) Typologies
The FBI Internet Crime Complaint Center (IC3) ranks Business Email Compromise (BEC)—termed Email Account Compromise (EAC) when internal credentials are breached—as the costliest cyber threat facing modern organizations. Crucially, BEC attacks rarely deploy malware or suspicious URLs; they manipulate business processes through four primary typologies:
- CEO Fraud / Executive Impersonation: Adversaries impersonate top executives, directing accounting personnel to execute urgent, confidential wire transfers for unannounced corporate acquisitions or emergency supplier debts, forbidding secondary verification under non-disclosure constraints.
- Vendor Email Compromise (VEC) / Supplier Invoice Fraud: Attackers compromise an established supplier's email account. By monitoring ongoing correspondence, they intercept billing discussions and submit modified invoices with attacker-controlled bank routing details. Because messages originate from authentic vendor mailboxes with valid SPF/DKIM records, email gateways deliver them.
- Payroll Diversion: Attackers impersonate employees, requesting that HR or payroll personnel update direct deposit bank accounts immediately before scheduled payroll runs.
- Attorney Impersonation: Adversaries pose as external legal counsel managing confidential litigation or regulatory audits, pressuring staff to remit funds or transfer sensitive data under threat of legal default.
Technical Mechanisms of Email Spoofing
Email spoofing falsifies message origin metadata to deceive recipients. Defenders encounter four distinct spoofing mechanisms:
- Display Name Spoofing: Exploits the RFC 5322 distinction between the friendly display name and mailbox address. Attackers set the display name to a trusted executive while using an external account (e.g.,
"Jane Doe, CEO" [attacker@external-mail.com]). Because mobile clients truncate headers to show only the display name, recipients overlook the external address. - Exact Domain Spoofing: Attackers insert the target's exact domain into the RFC 5322
From:header (From: ceo@victimcorp.com). This succeeds when the victim domain lacks an enforced Sender Policy Framework (SPF) or Domain-based Message Authentication, Reporting, and Conformance (DMARC) policy. - Lookalike and Typosquatting Domains: Attackers register domains mimicking targets through character substitutions, transpositions, or homoglyphs (e.g.,
examp1e.comor Internationalized Domain Name IDN homograph attacks where Cyrillic letters visually imitate Latin characters). - Cousin Domains: Legitimate-looking domains combining corporate brand names with operational terms (e.g.,
victimcorp-billing.com,victimcorp-portal.net). Attackers configure legitimate DNS, SPF, and DKIM records for these domains, establishing high deliverability and bypassing basic reputation filters.
Advanced Credential Harvesting: Reverse Proxy AitM Phishing
Traditional static phishing pages harvest usernames and passwords but fail against Multi-Factor Authentication (MFA). To defeat MFA defenses, adversaries deploy Adversary-in-the-Middle (AitM) reverse proxy frameworks (such as Evilginx2, Modlishka, and Muraena):
- Proxy Positioning: The attacker deploys a reverse proxy beneath a lookalike or cousin domain secured with valid SSL/TLS certificates.
- Real-Time Traffic Relay: When a victim navigates to the phishing link, the proxy fetches authentic login pages directly from the target's Identity Provider (IdP, such as Microsoft Entra ID or Okta) and renders them to the victim.
- MFA Relay: The victim submits credentials, which the proxy passes to the authentic IdP. The IdP issues an MFA challenge (SMS OTP, TOTP code, or push prompt) which the proxy relays back to the victim.
- Session Token Capture: Once the victim completes MFA, the IdP generates authenticated session cookies (such as
ESTSAUTHandESTSAUTHPERSISTENT). The reverse proxy intercepts and logs these session tokens before redirecting the victim to the authentic corporate portal. - Session Hijacking: The attacker imports stolen session cookies into their browser, hijacking the active session without needing the victim's MFA token, successfully bypassing non-FIDO2 MFA.
Malicious Attachment Delivery Vectors and Filter Evasion
Adversaries continually adapt attachment formats to evade Secure Email Gateway (SEG) sandboxes and endpoint security controls:
- Macro-Enabled Documents: Office documents (
.docm,.xlsm) containing Visual Basic for Applications (VBA) or Excel 4.0 (XLM) macros. Macros invoke native tools (PowerShell,cmd.exe) to download external payloads. - Mark-of-the-Web (MotW) Evasion: Windows tags downloaded files with a
Zone.IdentifierAlternate Data Stream (Zone ID 3), prompting Protected View and blocking macro execution. Attackers evade MotW using specialized containers:- ISO, VHD, and IMG Disk Images: Double-clicking disk images automatically mounts them as virtual drives. In legacy or unpatched Windows environments, files inside mounted images did not inherit MotW, allowing embedded executables or shortcuts to execute without security prompts.
- Windows Shortcut (LNK) Files: Malicious
.lnkshortcuts disguised with document or folder icons execute obfuscated PowerShell or MSHTA command lines to retrieve remote payloads. - Password-Protected Archives: Encrypted ZIP or RAR archives where the decryption password is supplied in the email body or image. Automated gateway sandboxes cannot decrypt the archive, allowing malicious payloads to land uninspected in user mailboxes.
An incident handler discovers that an employee's cloud email account was compromised despite having multi-factor authentication (MFA) with time-based one-time passwords (TOTP) enabled. Telemetry reveals that the user clicked an email link to a lookalike domain, entered their credentials, and completed the MFA prompt, after which an external IP address accessed the mailbox using an existing authenticated session token without triggering a secondary MFA prompt. Which attack mechanism was deployed?
An Adversary-in-the-Middle (AitM) reverse proxy such as Evilginx2 that relayed authentication requests and captured valid session cookies
A localized keylogger installed via a macro-enabled Word document that recorded keystrokes
A brute-force password spraying attack that bypassed the identity provider's lockout policies
A DNS cache poisoning exploit that redirected corporate MX records to a rogue mail transfer agent
A threat actor compromises the legitimate Microsoft 365 account of an enterprise's external IT hardware vendor. The attacker observes an ongoing email correspondence between the vendor's billing department and the enterprise's procurement team regarding an outstanding $240,000 server purchase. The attacker replies directly within the legitimate thread, attaching an altered PDF invoice instructing the enterprise to remit payment to a new banking routing number. How is this attack categorized?
Executive Whaling
Vendor Email Compromise (VEC)
Display Name Spoofing
Payroll Diversion Fraud
During an incident investigation, a security analyst examines a spear phishing email delivering an attachment named Statement_Q3.iso. Why did the threat actor package the payload inside an ISO disk image container rather than attaching an executable or raw macro-enabled document directly?
ISO files automatically escalate local privileges to NT AUTHORITY\SYSTEM when opened
Disk images bypass transport-layer TLS encryption during mail delivery
Mounting the disk image bypassed Mark-of-the-Web (MotW) propagation on legacy systems and evaded basic gateway filters
ISO containers permanently disable endpoint antivirus real-time scanning engines upon receipt
Sections you finish are checked off in the contents.