Embedded Email Attacks Are on the Rise and Aren’t Being Detected by Security Solutions

Stu Sjouwerman | Dec 20, 2021

embedded-email-attackThis classic tactic is making a comeback and is elegantly simple to execute, yet sufficiently complex enough to keep email scanning solutions from seeing it as malicious.

Malicious attachments are nothing new; there are countless examples of how threat actors embed malicious code, links, etc. into attachments as the delivery vehicle. Most email scanning solutions either scan attachments or “detonate” them in a virtual sandbox to see the behavior of the attachment once run.

But an old method of embedding malicious content is making a comeback, according to security researchers at Avanan. This method places the malicious content into an .eml file (which is interpreted as an email) and can contain plain ASCII text for the headers and the main message body as well as hyperlinks and attachments) and then the .eml file is attached to the phishing email itself.

The end result is security solutions “overlook” the malicious content within the .eml file, leaving the threat actor with a viable mechanism to move the would-be victim towards performing the needed malicious action – be it clicking a link, opening a webpage, or providing credentials.

In the case of the example provided by Avanan, the .eml file points the victim to a supposed PDF file using Office 365 branding to establish legitimacy. Upon clicking the link to see the bogus PDF, an impersonated Office 365 logon screen is provided to capture user’s credentials.

The .eml angle is pretty dangerous. While it’s not often we as business professionals send an email as an attachment to another email – but it does happen, making it not completely inappropriate for a user to see this kind of email in the wild.

Users need to be educated on these kinds of tactics and to maintain a sense of vigilance with Security Awareness Training so that they treat emails like these – that seem just a bit out of the ordinary – as suspicious from the start, helping to minimize the risk that they fall for the scam.

Topics: Phishing

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.