Email Hiding Rules

T1564.008

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email functions, including moving emails to other folders, marking emails as read, or deleting emails. Rules may be created or modified within email clients or through external features such as the New-InboxRule or Set-InboxRule PowerShell cmdlets on Windows systems.

Adversaries may utilize email rules within a compromised user's mailbox to delete and/or move emails to less noticeable folders. Adversaries may do this to hide security alerts, C2 communication, or responses to Internal Spearphishing emails sent from the compromised account.

Any user or administrator within the organization (or adversary with valid credentials) may be able to create rules to automatically move or delete emails. These rules can be abused to impair/delay detection had the email content been immediately seen by a user or defender. Malicious rules commonly filter out emails based on key words (such as malware, suspicious, phish, and hack) found in message bodies and subject lines.

In some environments, administrators may be able to enable email rules that operate organization-wide rather than on individual inboxes. For example, Microsoft Exchange supports transport rules that evaluate all mail an organization receives against user-specified conditions, then performs a user-specified action on mail that adheres to those conditions. Adversaries that abuse such features may be able to automatically modify or delete all emails related to specific topics (such as internal security incident notifications).

Detection rules3

Rules on DetectionCode tagged with T1564.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
O365 BEC Email Hiding Rule CreatedTTPNULL
O365 Email New Inbox Rule CreatedAnomalyNULLOffice 365 Universal Audit Log
O365 Email Transport Rule ChangedAnomalyNULLOffice 365 Universal Audit Log

Groups2

Software1

Campaigns0

None recorded.

Procedure examples3

Groups2

Used byProcedure example
GroupFIN4

FIN4 has created rules in victims' Microsoft Outlook accounts to automatically delete emails containing words such as “hacked," "phish," and “malware" in a likely attempt to prevent organizations from communicating about their activities.

GroupScattered Spider

Scattered Spider creates inbound rules on the compromised email accounts of security personnel to automatically delete emails from vendor security products.

Software1

Used byProcedure example
MalwareKali365

Kali365 has the ability to modify email rules to delete email based notifications prior to the victim seeing them.

References6

  1. MacOS Email Rules Open source
    Apple. (n.d.). Use rules to manage emails you receive in Mail on Mac. Retrieved June 14, 2021.
  2. Microsoft Cloud App Security Open source
    Niv Goldenberg. (2018, December 12). Rule your inbox with Microsoft Cloud App Security. Retrieved June 7, 2021.
  3. Microsoft Inbox Rules Open source
    Microsoft. (n.d.). Manage email messages by using rules. Retrieved June 11, 2021.
  4. Microsoft Mail Flow Rules 2023 Open source
    Microsoft. (2023, February 22). Mail flow rules (transport rules) in Exchange Online. Retrieved March 13, 2023.
  5. Microsoft New-InboxRule Open source
    Microsoft. (n.d.). New-InboxRule. Retrieved June 7, 2021.
  6. Microsoft Set-InboxRule Open source
    Microsoft. (n.d.). Set-InboxRule. Retrieved June 7, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.