logo

Embedded Threats: How Attackers Weaponize Legitimate Emails

ID: 69d39d27-c7f0-52b7-9045-7cd336fa2c22

STIX ID: report--69d39d27-c7f0-52b7-9045-7cd336fa2c22

Feed Name: Cofense Blog

Threat Score
65/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Cofense

...
...

This Cofense Intelligence report details a tactic in which attackers register accounts or use arbitrary text fields (usernames, meeting descriptions, file names, custom images) on legitimate services—highlighting Zoom—to embed malicious links or phone scams into emails that are then forwarded to victims. Because the emails originate from legitimate services, they preserve valid From addresses and pass DKIM/DMARC/SPF checks, making detection difficult; examples include meeting invites and account-change notifications used to deliver ConnectWise RAT. The report explains the attack flow, common abused services and fields, and recommends contextual threat intelligence and user awareness training as primary mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.