Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.
Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.
“ReliaQuest identified numerous instances of this empty-envelope pattern over the past year, frequently used against executives, managers, and business-facing roles,” the researchers write. “In one case, a message failed every sender authentication check and was classified as high-confidence phishing but still reached the inbox because the spoofed executive address was listed as an allowed sender. Defenders should therefore treat filtering exceptions as high-risk trust decisions, particularly when they cover privileged or frequently impersonated users.” The attacks observed by ReliaQuest used routine phishing lures that employees would expect to see throughout their workdays.
“The delivered emails used familiar business themes rather than technically sophisticated lures,” ReliaQuest says. “Document and file-sharing notifications were the most common, followed by payment and remittance requests, procurement invitations, loan and investment offers, and a meeting invitation. These themes blend into routine workflows and give recipients a plausible reason to open a document, follow a link, or act on a financial request. Multiple cases used SVG (graphics file type) attachments presented as voicemail recordings, combining a familiar notification theme with a browser-rendered file format that security products may handle inconsistently.” The phishing emails are targeting employees who handle financial responsibilities, attempting to trick them into authorizing payments or sending sensitive information.
“ReliaQuest assesses with moderate confidence that attackers in the cases we investigated favored recipients who routinely process invoices, bids, payment instructions, and externally shared documents,” the researchers write. “Attackers likely target these users because their authority and routine responsibilities make financial and document-sharing lures more credible, and a successful compromise can enable fraudulent payments, sensitive data theft, or further access. Procurement and customer-facing mailboxes are also attractive targets because they routinely receive unfamiliar external messages that multiple users may need to act on. Permissive allow rules for these identities can further increase the risk by giving attackers a repeatable way to deliver phishing under a trusted internal address.”
ReliaQuest has the story: https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control/
