Query Details

Multi Stage Social Engineering Attack Mail Bombing External Teams Phishing And RMM Execution

Query

// Config
let Lookback           = 4h;
let MailThreshold      = 100;
let MailTimeWindow     = 30m;
let FloodToTeamsWindow = 2h;
let TeamsToRMMWindow   = 2h;
let MinSenderDomains   = 20;
let InternalDomains = dynamic([
    "domain.ch", "students.domain.ch", "other-domain.ch"
]);
// Windows RMM binaries
let RMMProcessesWin = dynamic([
    "quickassist.exe", "teamviewer.exe", "anydesk.exe",
    "screenconnect.client.exe", "screenconnect.clientservice.exe",
    "rustdesk.exe", "splashtop.exe", "logmein.exe",
    "ateraagent.exe", "syncro.exe", "supremo.exe"
]);
// macOS RMM binaries 
let RMMProcessesMac = dynamic([
    "TeamViewer", "TeamViewer_Desktop", "TeamViewer_Service",
    "AnyDesk", "RustDesk", "rustdesk",
    "ScreenConnect Client", "ConnectWiseControl", "connectwisecontrol",
    "SRStreamer", "Splashtop Streamer", "SplashtopStreamer",
    "LogMeIn", "LMIGUIAgent", "GoToAssist",
    "Supremo", "AteraAgent", "Syncro",
    "ZohoAssist", "Zoho Assist", "ZA_Connect",
    "NetSupport", "client32",
    "remoting_me2me_host", "dwagent", "dwagsvc"
]);
// Vendor tokens for path matches in /Applications
let RMMVendorsMac = dynamic([
    "TeamViewer", "AnyDesk", "RustDesk", "ScreenConnect", "ConnectWise",
    "Splashtop", "Supremo", "Zoho", "NetSupport", "LogMeIn", "GoToAssist",
    "Atera", "Syncro", "DWAgent"
]);
// Native macOS remote access tools used by attackers
let MacNativeBins = dynamic(["kickstart", "systemsetup", "screensharingd", "ARDAgent"]);
let MacNativeArgs = dynamic(["-activate", "-setremotelogin on", "-configure", "-allowAccessFor"]);
// MDM engines that legitimately run kickstart/systemsetup
let MacMgmtParents = dynamic(["jamf", "jamfAgent", "jamfManagementService", "munki", "managedsoftwareupdate", "intunemdmagent"]);
// Detect mail flooding
let MailFloodedUsers =
    EmailEvents
    | where TimeGenerated > ago(Lookback)
    | where EmailDirection == "Inbound"
    | summarize IncomingMails = count(), SenderDomains = dcount(SenderFromDomain)
        by RecipientEmailAddress, Bucket = bin(TimeGenerated, MailTimeWindow)
    | where IncomingMails >= MailThreshold
    | where SenderDomains >= MinSenderDomains
    | summarize FirstFloodTime = min(Bucket), TotalFloodMails = sum(IncomingMails),
                DistinctSenderDomains = max(SenderDomains)
        by TargetUpn = tolower(RecipientEmailAddress)
    | extend UserKeys = pack_array(TargetUpn, tostring(split(TargetUpn, "@")[0]));
// Find Teams messages sent from external addresses
let ExternalTeamsChats =
    MessageEvents
    | where TimeGenerated > ago(Lookback)
    | where isempty(GroupId)
    | where SenderType =~ "User"
    | extend SenderAddress = tolower(tostring(SenderEmailAddress))
    | extend SenderDomain  = tostring(split(SenderAddress, "@")[1])
    | where isnotempty(SenderDomain)
    | where SenderDomain !in~ (InternalDomains)
    | mv-expand Recipient = RecipientDetails
    | extend TargetUpn    = tolower(tostring(Recipient.RecipientSmtpAddress))
    | extend TargetDomain = tostring(split(TargetUpn, "@")[1])
    | where TargetDomain in~ (InternalDomains)
    | project TeamsTime = TimeGenerated, TargetUpn,
              ExternalSender = SenderAddress, ExternalSenderDomain = SenderDomain,
              IsExternalThread, IsOwnedThread, ThreadId, ThreadType,
              ChatSubject = Subject, DeliveryAction;
// OS platform enrichment
let DevicePlatform =
    DeviceInfo
    | where TimeGenerated > ago(Lookback)
    | summarize arg_max(TimeGenerated, OSPlatform) by DeviceId
    | project DeviceId, OSPlatform;
// Track RMM execution (Windows + macOS)
let RMMExecutions =
    DeviceProcessEvents
    | where TimeGenerated > ago(Lookback)
    | extend MacPathHit = FolderPath contains "/Applications/" and FolderPath has_any (RMMVendorsMac)
    | extend MacNativeHit = FileName in~ (MacNativeBins)
                            and ProcessCommandLine has_any (MacNativeArgs)
                            and InitiatingProcessFileName !in~ (MacMgmtParents)
    | where FileName in~ (RMMProcessesWin) or InitiatingProcessFileName in~ (RMMProcessesWin)
         or FileName in~ (RMMProcessesMac) or InitiatingProcessFileName in~ (RMMProcessesMac)
         or MacPathHit
         or MacNativeHit
    | extend RMMProcess = case(
          FileName in~ (RMMProcessesWin) or FileName in~ (RMMProcessesMac) or MacNativeHit, FileName,
          MacPathHit, FileName,
          InitiatingProcessFileName)
    | extend AccessMethod = case(
          MacNativeHit, "macOS native remote access enabled",
          "Third-party RMM")
    | lookup kind=leftouter DevicePlatform on DeviceId
    | extend UserKey = tolower(iff(isnotempty(AccountUpn), AccountUpn, AccountName))
    | where isnotempty(UserKey)
    | project RMMTime = TimeGenerated, DeviceName, DeviceId, OSPlatform, UserKey,
              RMMProcess, AccessMethod, FileName, FolderPath,
              ProcessCommandLine, InitiatingProcessFileName;
// Correlation
MailFloodedUsers
| join kind=inner ExternalTeamsChats on TargetUpn
| where TeamsTime >= FirstFloodTime and TeamsTime <= FirstFloodTime + FloodToTeamsWindow
| mv-expand UserKey = UserKeys to typeof(string)
| join kind=inner RMMExecutions on UserKey
| where RMMTime >= TeamsTime and RMMTime <= TeamsTime + TeamsToRMMWindow
| summarize FloodStartTime        = min(FirstFloodTime),
            MailVolume            = max(TotalFloodMails),
            SenderDomains         = max(DistinctSenderDomains),
            FirstTeamsChat        = min(TeamsTime),
            ExternalTeamsSender   = make_set(ExternalSender, 10),
            ExternalSenderDomains = make_set(ExternalSenderDomain, 10),
            ChatSubjects          = make_set(ChatSubject, 5),
            ThreadTypes           = make_set(ThreadType, 5),
            RMMExecutionTime      = min(RMMTime),
            FolderPaths           = make_set(FolderPath, 5),
            CommandLines          = make_set(ProcessCommandLine, 5)
    by TargetUpn, DeviceName, Platform = coalesce(OSPlatform, "unknown"), RMMProcess, AccessMethod
| extend Verdict = "Social engineering chain: Mail flood, external Teams chat, RMM launch"
| sort by RMMExecutionTime desc

About this query

Multi-Stage Social Engineering Attack: Mail Bombing, External Teams Phishing, and RMM Execution

Query Information

MITRE ATT&CK Technique(s)

Technique IDTitleLink
T1566.003Phishing: Spearphishing via Servicehttps://attack.mitre.org/techniques/T1566/003/
T1219Remote Access Toolshttps://attack.mitre.org/techniques/T1219

Description

This rule detects a multi-stage attack chain characterized by an email flooding attack (mail bombing) against a user, followed by unsolicited external Microsoft Teams messages targeting that same user, and culminating in the execution of Remote Monitoring and Management (RMM) software on the user's device. This pattern is indicative of a social engineering campaign where attackers distract the user with a high volume of emails to hide malicious communications and subsequently pressure the user into executing unauthorized remote access tools.

Author <Optional>

Defender XDR

Explanation

This query is designed to detect a specific type of multi-stage cyber attack that involves social engineering tactics. Here's a simplified breakdown of what the query does:

  1. Objective: The query aims to identify a sequence of malicious activities targeting a user, which includes:

    • An email flooding attack (mail bombing) to overwhelm the user with a large number of emails.
    • Unsolicited messages sent via Microsoft Teams from external sources to the same user.
    • Execution of Remote Monitoring and Management (RMM) software on the user's device, which could allow unauthorized remote access.
  2. Steps Involved:

    • Mail Bombing Detection: The query first identifies users who receive an unusually high volume of emails from a large number of different domains within a short time frame (30 minutes). This is indicative of a mail bombing attack.
    • External Teams Phishing: It then checks for any Microsoft Teams messages sent to these users from external domains (not belonging to the organization) within 2 hours after the mail bombing.
    • RMM Execution: Finally, it looks for the execution of known RMM software on the user's device within 2 hours after receiving the Teams messages. This step checks both Windows and macOS platforms for known RMM binaries.
  3. Correlation: The query correlates these events to confirm the attack chain. It ensures that the Teams messages follow the mail bombing and that the RMM execution follows the Teams messages within specified time windows.

  4. Output: If all these conditions are met, the query outputs details of the attack chain, including:

    • The start time of the mail flood.
    • The volume of emails and number of sender domains.
    • Details of the external Teams messages (senders, domains, subjects).
    • The time and details of the RMM execution (process name, method of access).
    • A verdict indicating the detection of a social engineering attack chain.

This query helps security teams identify and respond to complex social engineering attacks that use multiple stages to compromise a user's device.