Huntress details a real-world business email compromise (BEC) attack caught during beta testing of their MDR for Microsoft 365 product. A threat actor logged in from a Nigerian IP address, created obfuscated inbox rules with keyboard-walk names (e.g., 'jkhjg', 'm,bvc') to silently move emails to the rarely-visited Conversation History folder, and set up forwarding rules targeting finance and operations staff at multiple companies. The goal was to intercept vendor invoices and redirect payments to attacker-controlled accounts. Key detection signals include inbox rules routing mail to the Conversation History folder and short nonsensical rule names paired with Mark as Read actions. The post includes IoCs and MITRE ATT&CK TTPs.

5m read timeFrom huntress.com
Post cover image
Table of contents
Setting the StageAttacker MotivationsSummary of the AttackAnalysis of Threat Actor ActionsParting Thoughts
1 Impression