Inboxfuscation: Because Rules Are Meant to Be Broken
Credits: Dominique Parker & Wilma Miranda
Microsoft Exchange inbox rules have emerged as a critical attack vector for advanced persistent threat (APT) groups seeking to establish persistence and facilitate data exfiltration within enterprise environments. Our research introduces Inboxfuscation, a sophisticated Unicode-based obfuscation technique that is able to create malicious inbox rules that evade detection by traditional security monitoring systems.
This analysis examines the technical imple...
Read more at permiso.io