Filters
Reset
Attack Type
Attack Vector
Attack Goal
Attack Tactic
Impersonated Party
Attachment Type
Language
Theme
Impersonated Brand
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Attack Vault

Showing
X
results

The Attack Vault contains samples of email-based cyber attacks targeting enterprise users, including business email compromise (BEC) attacks, financial supply chain fraud, credential phishing, malware attacks, and other types of scams. The email subject and body content of these samples can be searched and the repository can be filtered based on specific characteristics using the options below.

This collection of attack samples is not meant to be a comprehensive repository of all email-based threats. Rather, the Attack Vault contains a cross-section of various types of cyber threats--each containing a unique combination of tactics, themes, and/or content--to provide a general overview of some of the more notable attacks observed in today's email threat landscape.

Good evening


Right here I direct you all the necessary records regarding our soon meeting, right as we revealed recently. Please review the аll required data here:



hXXps://furatfashionstudio[.]co[.]in/aeu/cuteototeenrsvercnin


File password: U523



[Hijacked threat content]

Fake Document Link-based Malware Attack

Subject:
"
Re: [Hijacked Threat Subject]
"
Attack Date:
June 28, 2022

This link-based attack uses a hijacked email thread and a fake document theme to deliver malware.

No items found.
Type:
Malware
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Malware Delivery
Impersonated Party:
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Image with text content]


Thank you!

Norton Fake Payment Receipt Fake Billing Scam

Subject:
"
Thank you for your payment
"
Attack Date:
June 28, 2022

This text-based fake billing scam impersonates Norton using a content obfuscation via image and a fake payment receipt theme.

No items found.
Type:
Fake Billing Scam
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Impersonated Party:
Impersonated Brand:
Norton
Attachment Type:
Language:
See Attack Details

Hi,


Please find attached your Shipping documents.


Kindly do the needful.


Regards,


[Third Party Employee Name]

Coordinator, Shipment Office

DHL Express (AE) LLC

DHL Fake Shipping Notification HTML Attachment Credential Phishing Attack

Subject:
"
Shipment Details
"
Attack Date:
June 28, 2022

This payload-based attack impersonates DHL using a free webmail account and a fake shipping notification theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Payload-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
DHL
Attachment Type:
HTML
Language:
See Attack Details

Hoi [Recipient First Name]

  Wat is je telefoon nummer? Uw aandacht is nodig om meteen een taak voor mij af te handelen.


Vriendelijke groeten,

Bedankt.


Verzonden vanaf mijn mobiele apparaat.



Kind Regards

Dutch Executive Impersonation Gift Card Request BEC Attack

Subject:
"
[Recipient First Name]
"
Attack Date:
June 28, 2022

This text-based Dutch-language BEC attack impersonates an executive using a personalized email subject, a cell phone number request, a spoofed display name, and a free webmail account to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
Dutch
See Attack Details

[Target Company Name] Verification Expires 01 July, 2022


Hi [Recipient Username],


Your password for your email account [Recipient Email Address] will expire on 01 July, 2022.

To continue using your account [Recipient Email Address] Please reconfirm account ownership below.


Reconfirm Password


[Target Company Name] Mail Team

Message securely sent to [Recipient Email Address], please ignore if wrongly received.

Expired Account Credential Phishing Attack

Subject:
"
[Target Company Name] Urgent deactivation alert
"
Attack Date:
June 28, 2022

This link-based attack uses a personalized email subject, a maliciously registered domain, and an expired account theme to steal credentials.

No items found.
Type:
Credential Phishing
Theme(s):
...
Tactic(s):
...
Vector:
Link-based
Goal:
Credential Theft
Impersonated Party:
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Recipient First Name],


Need you to initiate a wire transfer today, how soon can you get this done

So i can send the information required 


Regards



[Executive Name]


Sent from my iPhone 

Executive Impersonation Payment Fraud BEC Attack

Subject:
"
FYI !!!
"
Attack Date:
June 28, 2022

This text-based BEC attack impersonates an executive using a spoofed email address, a matching malicious domain username, and a maliciously registered domain to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

[Recipient First Name],

I need your help to resolve an urgent matter by the close of business today.

Please let me know your available time slots for a conference call later today and the number to reach you at.


Thanks,

[Executive First Name]



Sent from my iPhone

Executive Impersonation Payment Fraud BEC Attack

Subject:
"
Availability
"
Attack Date:
June 27, 2022

This text-based BEC attack impersonates an executive using a spoofed email address and a maliciously registered domain to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Hast du eine Minute ?

Ich brauche Sie, um eine Aufgabe für mich zu erledigen, wenn Sie verfügbar sind.

 

 

Gesendet von einem drahtlosen 5G-Gerät

German Executive Impersonation Gift Card Request BEC Attack

Subject:
"
ANFRAGE
"
Attack Date:
June 27, 2022

This text-based German-language BEC attack impersonates an executive using a spoofed display name and a free webmail account to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
German
See Attack Details

Hei [Recipient First Name],


Oletko käytettävissä juuri nyt? Minulla on tänään pari kokousta koko

päivän, ja sinun on suoritettava minulle henkilökohtaisesti tehtävä

mahdollisimman pian. Joten olisin kiitollinen nopeasta

sähköpostivastauksesta.


Parhain terveisin,


[Executive First Name].



Lähetetty iPhonestani 

Finnish Executive Impersonation Gift Card Request BEC Attack

Subject:
"
Hei [Recipient First Name]
"
Attack Date:
June 27, 2022

This text-based Finnish-language BEC attack impersonates an executive using a personalized email subject, an external compromised account, and a spoofed display name to request the purchase of gift cards.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Gift Card Request
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
Finnish
See Attack Details

Hi [Recipient First Name],

 

Can you set up a faster payment for the overdue attached invoice?

 

It needs to be paid immediately.

 

Kindly Advise.

 

Thanks.

 

[Executive Name]

[Executive Title]

Executive Impersonation Overdue Payment Payment Fraud BEC Attack

Subject:
"
Re: SIN008750-June-2022
"
Attack Date:
June 27, 2022

This text-based BEC attack impersonates an executive using a spoofed display name, a free webmail account, and an overdue payment theme to request a fraudulent payment.

No items found.
Type:
Business Email Compromise
Theme(s):
...
Tactic(s):
...
Vector:
Text-based
Goal:
Payment Fraud
Impersonated Party:
Employee - Executive
Impersonated Brand:
Attachment Type:
Language:
See Attack Details

Whoops.. There are no results found.