Attackers are continually finding new ways to refine business email compromise (BEC) attacks, according to Douglas McKee, Director of Vulnerability Intelligence at Rapid7.
When attackers compromise trusted tools and accounts, they can manipulate victims’ view of reality. One way attackers can achieve this is through what McKee calls “calendar warfare,” in which attackers use calendar meetings to trick users into falling for attacks.
“Meetings can be modified or deleted without generating the notification trail users expect to see. RSVP status can also be flipped,” McKee writes. “Maybe a key executive is changed from Accepted to Declined and leadership might reschedule, or move ahead without them, or read the whole thing as a deliberate opt-out. It works in the other direction too. An ‘Emergency Board Meeting’ lands on an executive's calendar with a believable organizer, a popup reminder, and a malicious Zoom link. When the reminder fires, the victim is not sizing up a suspicious email that arrived thirty seconds ago. They are joining a meeting that has been sitting in their calendar for two days.”
Likewise, when an attacker compromises a trusted account and uses it to send legitimate-looking communications, the victim themselves may not realize that someone else is using their account.
“Send an email as your CFO without ever touching their password, and you have the front half of a very convincing BEC,” McKee says. “Keep control of the mailbox afterward and you have the back half, too. Here, the attacker has a strategic choice. They can delete the sent message to hide their tracks, effectively wiping the trail of the fraud OR they can choose to leave the message in the Sent Items folder. By doing so, they ensure the CFO sees 'evidence' of the email they supposedly sent, creating a gaslighting scenario where the victim is left questioning their own actions.”
Rapid7 has the story: https://www.rapid7.com/blog/post/ve-business-email-compromise-rewriting-reality-zimbra-cve/
