Social engineering a hotel is downright inhospitable

No ratings

Presented at SaintCon 2024 by

Spam filtering tools are now extremely adept at blocking unsolicited emails cattying attachments that come from accounts you haven't interacted with. So if you're an enterprising malware gang, how to you get around the problem? Apparently, one way to successfully do it is to engage with the target in a benign email conversation first, which establishes a message history between the target and attacker, and wears down a spam filter's resistance to subsequent emails, even if they have attachments. The research uncovered a series of attacks targeting specific kinds of businesses - hoteliers and tax accountants - in which the attackers leveraged this weakness in email protection by emailing the targets and cattying on a back-and-forth conversation before delivering the payload. Based on the messages we've seen, the attackers may have used generative AI to create realistic, grammatically correct messages. In the case of the attacks targeting hotels, the messages purport to come from a recent guest who alleges some form of wrongdoing by hotel staff. The wide variety of misbehavior the attacker accuses an unnamed staff member of doing - from racist attacks to allegations of violence - elicit an immediate response from hotel managers. In the attacks targeting tax preparers, the conversations are much more banal but ask for a quick response due to an impending deadline to file taxes. In both cases, the victim asks the attacker to send documentation, and the attacker responds with a malicious payload. In this talk, we'll explain how this technique upends algorithmic analysis of unsolicited email, and poses a vulnerability in modern email protection systems, where they fail to identify the final payload as malicious as a result of the conversation that precedes its delivery. We will also discuss the anti-analysis characteristics of the final payloads, which make it difficult for someone who is not a malware analyst to study or even validate as legitimate.