logo

Deceptive Signatures: Advanced Techniques in BEC Attacks

ID: 44e5111c-c128-567c-a62c-764234f1238d

STIX ID: report--44e5111c-c128-567c-a62c-764234f1238d

Feed Name: Cybereason Blog

Date Published: 2025-02-25

Date Updated: 2026-04-27

Author: Cybereason Consulting Team

...
...

This report details a Business Email Compromise tactic observed by Cybereason DFIR where attackers embed HTML-formatted phishing content into users’ email signature blocks, causing every outbound message to append a convincing lure that directs recipients to credential-harvesting Google Forms. The technique exploits trust, can continue even after password resets if signature changes go unnoticed, and enables cascading phishing from newly compromised accounts; recommended mitigations include advanced email filtering/ATP, user training, monitoring and alerting on signature changes, enforcing MFA, and testing BEC-focused incident response playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.