{"id":43397,"date":"2021-10-14T00:00:00","date_gmt":"2021-10-14T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/j\/analyzing-email-services-abused-for-business-email-compromise.html"},"modified":"2021-10-14T00:00:00","modified_gmt":"2021-10-14T00:00:00","slug":"analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/","title":{"rendered":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/j\/analyzing-email-services-abused-for-business-email-compromise\/cover-analyzing-types-of-email-services-abused-for-business-email-compromise-bec.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/j\/analyzing-email-services-abused-for-business-email-compromise\/cover-analyzing-types-of-email-services-abused-for-business-email-compromise-bec.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<div readability=\"33.870967741935\">\n<div readability=\"14.516129032258\">\n<p>The gradual increase throughout the year prompted us to pay attention to the campaigns being deployed, but the sudden increase in August caught our interest. Compared to campaigns from previous years in which BEC actors mostly impersonated executives or ranking management personnel, we observed a specific BEC campaign type spoofing general employees\u2019 display names. We noticed a sudden upshot of dangerous emails impersonating and targeting ordinary employees for money transfers, bank payroll account changes, or various company-related information. We launched the \u201c<a href=\"https:\/\/success.trendmicro.com\/solution\/000285799\">BEC Display Name Spoofing<\/a>\u201d detection solution for Trend Micro\u2122 Cloud App Security in Q1 to address this issue. Following this, we also observed the highest volume of BEC detections in the Americas.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36\">\n<div readability=\"17\">\n<p>BEC is an online scheme dependent on leveraging email and its features of convenience for legitimate users, and we noted five major types of email channels that BEC actors use. As we continue monitoring BEC operations, we also learned that BEC actors can use the same channels and techniques for a longer period than for just one deployment campaign, tracking complaints from different spoofed and scammed victims online. We also took note of the patterns in keywords and domain names that they use to appear legitimate to their potential victims, and what BEC email recipients can watch for when encountering these scams.<\/p>\n<p><span class=\"body-subhead-title\">Types of email services used for BEC<\/span>We analyzed the email services abused and the techniques that BEC actors have adopted in their campaigns.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"36.5\">\n<div readability=\"18\">\n<ol>\n<li><b>Free email services<\/b><\/li>\n<\/ol>\n<p>We observed BEC groups favoring the abuse of known free email services for the low-cost entry. There is also the trusted marketing quality and service promise of confidentiality in terms of protecting legitimate users, while bulk account creation tools can be used to facilitate numerous accounts. We observed services offered by Gmail, Hotmail, and Outlook as the top choices for BEC campaigns.<\/p>\n<p>These services allow BEC actors to spoof enterprise employees\u2019 names or personal emails to use. In a typical case of this type of abuse, malicious actors spoof an employee email address and request changes to payroll deposit bank accounts.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"39.5\">\n<div readability=\"24\">\n<p>We observed a part of the BEC chief executive officer (CEO) email fraud scheme includes having a common account naming convention, such as \u201coffice\u201d, \u201cpresident\u201d, \u201cchief\u201d, and \u201cdirector\u201d, among company leadership positions. Among all these free email services, Gmail appears to be the most commonly abused service for BEC during our investigation timeframe. We identified 10 commonly used examples:<\/p>\n<ol>\n<li>chiefexecutiveoffice &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>chiefexecutiveofficer &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>directorexecutiveofficer &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>officepresident &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>officepro &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>officeproject &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>officework &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>offshoreoffice &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>presidentoffice &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<li>rev.office &lt;BLOCKED&gt; [@]gmail.com<\/li>\n<\/ol>\n<p>More often, BEC email content usually includes direct financial requests or transfers from the intended victim. However, there are also indirect approaches wherein they first ask for specific favors from the recipient. If the recipient replies, it indicates that the potential victim believes that the sender is legitimate.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>We also observed some of these BEC email addresses being active from just a couple of days to years. For example, email account cexecutive9&lt;BLOCKED&gt;[@]gmail.com has been active for more than three years. We detected the address sending BEC emails in 1H 2018, and continued to see the same email account actively sending BEC more than three years later. We also noticed some users in social media complaining about an email scam received from the same address.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"40\">\n<div readability=\"25\">\n<p><b>2. Local email services<\/b><\/p>\n<p>Some services provide local email services for end users. BEC actors also frequently use these services (using either compromised credentials or making new ones) to launch BEC attacks. We observed more than 15 countries\u2019 local email services with BEC email footprints, such as the United States, United Kingdom, Germany, the Czech Republic, Poland, New Zealand, South Korea, Ukraine, Russia, Portugal, Australia, Norway, Italy, France, and Canada. Table 1 lists five of the email services and the BEC email sender account that we detected:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div class=\"responsive-table-wrap\" readability=\"7\">\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody readability=\"5\">\n<tr>\n<td width=\"208\" valign=\"top\">\n<p><b>Country<\/b><\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p><b>Email service<\/b><\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p><b>BEC email address<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"208\" valign=\"top\">\n<p>United Kingdom<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p>virginmedia.com<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\" readability=\"5\">\n<p>officelink &lt;BLOCKED&gt; [@]virginmedia.com<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"208\" valign=\"top\">\n<p>United States<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p>optimum.net<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\" readability=\"5\">\n<p>ceo &lt;BLOCKED&gt; [@]optimum.net<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"208\" valign=\"top\">\n<p>Czech Republic<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p>seznam.cz<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\" readability=\"5\">\n<p>officeport &lt;BLOCKED&gt; [@]seznam.cz<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"208\" valign=\"top\">\n<p>Germany<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p>mail.com<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\" readability=\"5\">\n<p>officeonlyme &lt;BLOCKED&gt; [@]mail.com<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"208\" valign=\"top\">\n<p>South Korea<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\">\n<p>naver.com<\/p>\n<\/td>\n<td width=\"208\" valign=\"top\" readability=\"5\">\n<p>mail_ceoofficial &lt;BLOCKED&gt; [@]naver.com<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Table 1. Sample free email services and BEC email addresses used for campaigns<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"30.167400881057\">\n<div readability=\"8.4845814977974\">\n<p>We observed BEC email actors also being interested in victim&#8217;s contact information or data from companies such as <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/bec-scammers-use-aging-report-phishing-to-find-new-targets\/\">aging reports<\/a>. They also try to get information from their victims for other attacks that use social engineering.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p><b>3. Encrypted email services<\/b><\/p>\n<p>Like other cybercriminals, BEC actors also want to hide their footprints and prevent systems from tracking them. Encrypted email services provide users with a higher level of privacy and confidentiality (that is, the inclusion of other security features compared to other email services). We observed BEC actors using some encrypted email services and list some examples below:<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"31\">\n<div class=\"responsive-table-wrap\" readability=\"7\">\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody readability=\"3\">\n<tr>\n<td width=\"204\" valign=\"top\">\n<p><b>Encrypted email service<\/b><\/p>\n<\/td>\n<td width=\"210\" valign=\"top\">\n<p><b>Sample BEC email address<\/b><\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"204\" valign=\"top\">\n<p>Protonmail<\/p>\n<\/td>\n<td width=\"210\" valign=\"top\" readability=\"5\">\n<p>officeiccon &lt;BLOCKED&gt; [@]protonmail.com<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"204\" valign=\"top\">\n<p>Tutanota<\/p>\n<\/td>\n<td width=\"210\" valign=\"top\" readability=\"5\">\n<p>eye.adimn &lt;BLOCKED&gt; [@]tutanota.com<\/p>\n<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td width=\"204\" valign=\"top\">\n<p>Criptext.com<\/p>\n<\/td>\n<td width=\"210\" valign=\"top\" readability=\"5\">\n<p>iphone &lt;BLOCKED&gt; [@]criptext.com<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Table 2. Sample encrypted email services used for BEC<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33.5\">\n<div readability=\"12\">\n<p>These emails are not only found in the <i>From<\/i> email header, but at times also hidden in the <i>Reply-to<\/i> section. A common trick in email scams like BECs involves forging the From header into something legitimate-looking and hide the actors\u2019 actual email in a hidden Reply-to. &nbsp;When users directly reply just by clicking the in-mail Reply button, the Reply-to header will automatically be the recipient email address. This is unknown to the victim and it allows the BEC actor to communicate with the victim thereafter. The example in Figure 11 shows how a BEC actor hides the actual email address ceoof&lt;BLOCKED&gt;[@]protonmail.com in the Reply-to section.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"39.5\">\n<div readability=\"24\">\n<p><b>4. Self-registered domains and direct-to featured email service<\/b><\/p>\n<p>Aside from using globally known email services, BEC actors also register domains themselves. This can bring two benefits when they conduct attacks:<\/p>\n<p>1.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; They can create look-alike domains to deceive victims. The actors register domains with different characters but appear similar to a legitimate domain. Some commonly seen tricks include the interchange between specific letters and numbers:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">I (small letter L) \u2013 l (capital letter i) \u2013 1 (for example, example.com vs. exampIe.com vs. examp1e.com)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">o \u2013 0 (for example, trendmicro.com vs. trendmicr0.com)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">d \u2013 cl (for example, trendmicro.com vs. trenclmicro.com)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">m \u2013 rn (for example, example.com vs. exarnple.com)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">i \u2013 j (for example, trendmicro.com vs. trendmjcro.com)<\/span><\/li>\n<li><span class=\"rte-red-bullet\">g \u2013 q<\/span><\/li>\n<li><span class=\"rte-red-bullet\">u\u2013 v<\/span><\/li>\n<li><span class=\"rte-red-bullet\">w\u2013 vv<\/span><\/li>\n<\/ul>\n<p>Or the use of dashes (-) and periods (.) to separate a word or add a general postfix such as country codes (for example, example.com vs. example-tw.com). This trick is also widely used in other phishing schemes and other email-based scams, and will likely never get old.<\/p>\n<p>2.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Control positive email authentication results such as sender policy framework (SPF) or even DomainKeys Identified Mail (DKIM) while sending email to victims.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"49.221032132425\">\n<div readability=\"44.298928919182\">\n<p>While a SPF or DKIM pass does not indicate that an email is threat-free, it does provide an image that the sender is somehow legitimate, gaining the recipient\u2019s trust or even fool some anti-scam solutions.<\/p>\n<p><b>5. Stolen email credentials and email conversations<\/b><\/p>\n<p>BEC actors also launch attacks from compromised email accounts. In most instances using this technique, the malicious actors deploy a spam campaign with malicious attachments dropping keyloggers or trojan stealers like <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/h\/new-campaign-sees-lokibot-delivered-via-multiple-methods.html\">Lokibot<\/a>, <a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/threat-encyclopedia\/malware\/fareit\">Fareit<\/a>, backdoor <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/19\/h\/analysis-new-remcos-rat-arrives-via-phishing-email.html\">Remcos<\/a>, and <a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/news\/cybercrime-and-digital-threats\/negasteal-uses-hastebin-for-fileless-delivery-of-crysis-ransomware\">Negasteal<\/a> (Agent Tesla). These can steal credentials in applications like browsers, simple mail transfer protocol (SMTP), file transfer protocol (FTP), VPNs, and from computer and system information. The operators then harvest the credentials and try to log in to the mailbox or webmail. If successful, they can manipulate the hacked accounts to perform BEC deployments.<\/p>\n<p>From the compromised email account, BEC actors can also find email conversations related to finance- or purchase-themed threads such as purchase orders or invoices. Using these, they can create other spoofed email accounts, draft a reply with the stolen conversation, and start intercepting the conversation by replying to the recipients (usually suppliers). These are also called man-in-the-middle (<a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/news\/cybercrime-and-digital-threats\/infosec-guide-defending-against-man-in-the-middle-attacks\">MiTM<\/a>) attacks. In this case, BEC operators carefully study the targeted victims, potentially compromising the companies\u2019 email services. They will also look for unsuspecting suppliers or other involved recipients in the original email thread.<\/p>\n<p>Moreover, BEC operators use the username in the email resembling the victim\u2019s name or company name simultaneous to the email spoofing. In a few cases we observed, the malicious actors use customized usernames bearing the code \u201cgod\u201d in their email, marking the account as a carbon copy.<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;mygod@mail.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">godpls&lt;BLOCKED&gt;@mail.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;foods@post.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;elco@dr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;pala@dr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;zado@dr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">nicola&lt;BLOCKED&gt;@dr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">&lt;BLOCKED&gt;com-int@dr.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">ire&lt;BLOCKED&gt;@asia.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">julien&lt;BLOCKED&gt;@mail.com<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"43.144307856761\">\n<div readability=\"32.964190272582\">\n<p>The BEC actors can rent virtual private servers (VPS) with SMTP and remote desktop protocol (RDP) services. They can use email marketing software like <a href=\"https:\/\/www.gammadyne.com\/email_software.htm\">Gammadyne Mailer<\/a> to craft spam mails and send it to thousands of email addresses. These email addresses are harvested via tools such as <a href=\"https:\/\/www.lite14.us\/\">Email Extractor Lite<\/a>, while some come from spam activities. The actors can then review the stealer logs and identify mail servers of interest, which can contain conversations about purchasing orders. They can then hijack the email conversation, create spoofed emails, and use the conversation to deploy a BEC attack. Another method employed involves the tampering of the invoice document to reflect the BEC actors\u2019 bank account details. Thus, if there is a request for a wire transfer the money will go directly into their account.<\/p>\n<p><span class=\"body-subhead-title\">Keyword use and naming patterns<\/span><\/p>\n<p>We also observed some keywords or naming patterns that BEC actors generally use. We identified some of them and provide examples for each.<\/p>\n<p><b>1. Lengthy domain names with dashes (-)<\/b><\/p>\n<p>A group of BEC domains <a href=\"https:\/\/www.agari.com\/cyber-intelligence-research\/whitepapers\/acid-agari-exaggerated-lion.pdf\">operating from Africa<\/a> was observed to favor lengthy names, using new generic top-level domain (TLD) words such as \u201c[.]management\u201d, \u201c[.]work\u201d, or \u201c[.]one\u201d. Some domains also contain \u201c-\u201c and with common keywords such as \u201cmanagement\u201d, \u201cmail\u201d, \u201coffice\u201d, \u201creply\u201d, and \u201csecure\u201d. We list examples that we observed here:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">admin-office-mail-server-ssl0.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">reply-netsuite-mails.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">system-mail-protection-outlook.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">replys-mail-netsuite-com.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">systerm-proctection-outlook.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mails-officesslappssecure-serversportal-execs.management<\/span><\/li>\n<li><span class=\"rte-red-bullet\">reply-workplace-secure-protection-management-office.one<\/span><\/li>\n<li><span class=\"rte-red-bullet\">servermail-reply-office-works-secure-protecty-inbound-netsuite.one<\/span><\/li>\n<li><span class=\"rte-red-bullet\">office-xlsx-appspts-management-worksmailxls-cs.rest<\/span><\/li>\n<li><span class=\"rte-red-bullet\">office-mails-appsslz-workmail-management.work<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"35.5\">\n<div readability=\"16\">\n<p><b>2. The use of telecom keywords<\/b><\/p>\n<p>We also noticed BEC actors registering domain names with telecommunications industry-related keywords such as \u201c5g\u201d, \u201c4g\u201d, \u201cmobile\u201d, \u201cnetwork\u201d, and \u201cwireless\u201d. They occasionally include names of service providers such as \u201cVerizon\u201d and \u201cT-Mobile.\u201d It\u2019s also common to see dashes in domain names to increase the diversity of choices while registering:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">5g-verizou.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">network-sprint.biz<\/span><\/li>\n<li><span class=\"rte-red-bullet\">sprint-mobile.net<\/span><\/li>\n<li><span class=\"rte-red-bullet\">mobile-celldata.online.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">verizon-private-wireless.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">reply-tmobile.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">tmobilecellular.space<\/span><\/li>\n<li><span class=\"rte-red-bullet\">5g-tmobile.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">t-mobile4g-us.com<\/span><\/li>\n<li><span class=\"rte-red-bullet\">verizone4g-device.com<\/span><\/li>\n<\/ul><\/div>\n<\/p><\/div>\n<div readability=\"34.5\">\n<div readability=\"14\">\n<p>When we tracked \u201cTELE-COMM\u201d naming BEC domains\u2019 email infrastructure (observed from the domain name system mail exchanger or DNS MX records), we checked several commercial email services such as Google Workspace (aspmx.l.google.com) and Titan[.]email. These commercial email services provide advanced features like email tracking, scheduled sending, and follow-up reminders, and it is highly likely that BEC operators also optimize their operations\u2019 flow in leveraging these services.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"33\">\n<div readability=\"11\">\n<p>Below is an example of&nbsp;a BEC email initiating a conversation, wherein spaces are inserted in between words in the subject line. The word&nbsp;\u201cINVOICE\u201d&nbsp;is replaced with&nbsp;\u201cI NVOICE\u201d&nbsp;to evade&nbsp;anti-scam&nbsp;email solutions that rely on&nbsp;keywords&nbsp;or regular expressions.&nbsp;Similar&nbsp;tricks&nbsp;have been observed&nbsp;in sextortion&nbsp;and&nbsp;phishing email schemes.&nbsp;<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<div readability=\"52.286876355748\">\n<div readability=\"51.318600867679\">\n<p>Figure 17. A BEC email sender using separate words or letters in the subject line. Screenshot sourced from <a href=\"https:\/\/www.virustotal.com\/gui\/file\/8fd44022599427d1f3b4e83c42451b7823df34d39e09e33dbe2ff24747971361\">VirusTotal<\/a><\/p>\n<p><span class=\"body-subhead-title\">Conclusion<\/span><\/p>\n<p>Unlike other cybercriminal schemes, <a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/news\/cybercrime-and-digital-threats\/best-practices-identifying-and-mitigating-phishing-attacks\">phishing<\/a> and <a href=\"https:\/\/www.trendmicro.com\/vinfo\/tmr\/?\/us\/security\/news\/cybercrime-and-digital-threats\/how-to-spot-business-email-scam\">BEC scams<\/a> can be tricky to detect as they are targeted toward specific recipients. Attackers seek to compromise email accounts to gain access to financial and other sensitive information related to business operations, and BEC actors can easily use such access and information for other illicit activities. In the sample routines discussed here, the attackers\u2019 emails themselves do not include the typical malware payload of malicious attachments. As a result, traditional security solutions will not be able to protect accounts and systems from such attacks.<\/p>\n<p>From our observations, BEC attacks don\u2019t only target high-profile users but also any employee that can be found on social media networks with significant personal information published (such as LinkedIn). These pieces of information can be used to spoof employees and partners, and cause significant financial damage to businesses.<\/p>\n<p>As we observed professional email services being used for BEC attacks, we believe BEC actors will keep adopting new services and tools to optimize their operations flow as email services try to optimize services for their legitimate users. Targets in the Americas and Europe will continue to be targeted as sources of profit for these scams and will likely continue as companies see remote work becoming more mainstream, whether it be for their own operations or their managed service providers\u2019 (MSPs). &nbsp;Companies and employees will have to keep their guard up to mitigate the risks from BEC and other email-based scams:<\/p>\n<ul>\n<li><span class=\"rte-red-bullet\">Educate and train employees. Deflect company intrusions through continuous InfoSec education. All company personnel \u2014 from the CEO to rank-and-file employees \u2014 must be aware of the various techniques and kinds of scams, and the procedure to follow when they encounter an attack attempt.<\/span><\/li>\n<li><span class=\"rte-red-bullet\">Confirm requests using other channels. Avoid clicking on embedded links or directly replying to the email addresses used in the email. Exercise caution by following a verification system among employees who handle sensitive information, such as multiple personnel sign-off or additional verification protocols.<\/span><\/li>\n<li><span class=\"rte-red-bullet\"><b>Scrutinize all emails.<\/b> Be wary of irregular emails with suspicious content such as unknown and dubious sender emails, domain names, writing styles, and urgent requests. Report suspicious emails to the respective security and InfoSec teams for analysis, tracking, and blocking.<\/span><\/li>\n<\/ul>\n<p><span class=\"body-subhead-title\">Trend Micro solutions<\/span><\/p>\n<p>Trend Micro protects both small- to medium-sized businesses and enterprises against phishing- and BEC-related emails. Using enhanced machine learning combined with expert rules, <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps\/email-and-collaboration\/email-security.html\">Trend Micro\u2122 Email Security<\/a> solution analyzes both the header and the content of an email to stop BEC and other email threats. For source verification and authentication, it uses Sender Policy Framework (SPF), DomainKeys Identified Mail (DKIM), and Domain-Based Message Authentication, Reporting and Conformance (DMARC).<\/p>\n<p>The <a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/user-protection\/sps\/email-and-collaboration\/cloud-app-security.html\">Trend Micro\u2122 Cloud App Security<\/a> solution enhances the security of Microsoft Office 365 and other cloud services through sandbox malware analysis for BEC and other advanced threats. It uses Writing Style DNA, Display Name Spoofing, and High-Profile domain to detect BEC impersonations and computer vision to find credential-stealing phishing sites with <a href=\"https:\/\/docs.trendmicro.com\/en-us\/enterprise\/cloud-app-security-online-help\/advanced-threat-prot_001\/adding-atp-policies\/advanced-spam-protec.aspx\">Advanced Spam Protection<\/a> enabled. It also protects cloud file sharing from threats and data loss by controlling sensitive data usage.<\/p>\n<p><span class=\"body-subhead-title\">Indicators of Compromise (IOCs)<\/span><\/p>\n<p>For the full list of IOCs, you may download the text file <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/j\/analyzing-email-services-abused-for-business-email-compromise\/IOCs-analyzing-email-services-abused-for-BEC.txt\">here<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p>Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/j\/analyzing-email-services-abused-for-business-email-compromise.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We analyzed five major types of email channels, and the techniques in keywords and domain names BEC actors use to appear legitimate to potential victims. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":43398,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9521,9511,9508,9581,9585],"class_list":["post-43397","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-cyber-crime","tag-trend-micro-research-cyber-threats","tag-trend-micro-research-endpoints","tag-trend-micro-research-mobile","tag-trend-micro-research-spam"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-14T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"641\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher\",\"datePublished\":\"2021-10-14T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/\"},\"wordCount\":2543,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Cyber Crime\",\"Trend Micro Research : Cyber Threats\",\"Trend Micro Research : Endpoints\",\"Trend Micro Research : Mobile\",\"Trend Micro Research : Spam\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/\",\"name\":\"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg\",\"datePublished\":\"2021-10-14T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/","og_locale":"en_US","og_type":"article","og_title":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-10-14T00:00:00+00:00","og_image":[{"width":641,"height":350,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher","datePublished":"2021-10-14T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/"},"wordCount":2543,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Cyber Crime","Trend Micro Research : Cyber Threats","Trend Micro Research : Endpoints","Trend Micro Research : Mobile","Trend Micro Research : Spam"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/","url":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/","name":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg","datePublished":"2021-10-14T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher.jpg","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-email-services-abused-for-business-email-compromise-threats-analyst-threat-researcher-threats-analyst-sr-threat-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Analyzing Email Services Abused for Business Email Compromise Threats Analyst Threat Researcher Threats Analyst Sr. Threat Researcher"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43397","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43397"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43397\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/43398"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43397"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43397"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}