Deceptive Signatures: Advanced Techniques in BEC Attacks
ID: 44e5111c-c128-567c-a62c-764234f1238d
STIX ID: report--44e5111c-c128-567c-a62c-764234f1238d
Feed Name: Cybereason Blog
This report details a Business Email Compromise tactic observed by Cybereason DFIR where attackers embed HTML-formatted phishing content into users’ email signature blocks, causing every outbound message to append a convincing lure that directs recipients to credential-harvesting Google Forms. The technique exploits trust, can continue even after password resets if signature changes go unnoticed, and enables cascading phishing from newly compromised accounts; recommended mitigations include advanced email filtering/ATP, user training, monitoring and alerting on signature changes, enforcing MFA, and testing BEC-focused incident response playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
