Sinisterly
[need explanation] Intra mail loop Phishing - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: [need explanation] Intra mail loop Phishing (/Thread-need-explanation-Intra-mail-loop-Phishing)



[need explanation] Intra mail loop Phishing - MadLightning - 09-15-2022

Hi everyone !
This is my first post here, correct me and excuse me if i'm using the wrong sub-forum.

I'm asking for help to understand a kind of phishing i've been subject to and have never seen before.

I frequently receive mails in my professional box using the identity of one of our partner (administrive management) using a different adress everytime. Until there nothing new !

What makes me curious is that it directly responds in a mail loop between our company and the partner.
The phishing message is something like : Hey check this document out, there is an interesting information inside. And the attachment is a .html link that makes you download a .zip containing an infected iso. Hopefully i'm kinda aware about phishing so I haven't been trapped and informed my boss who's not that aware lol.

But my point is how did they slide INTO the mail loop ? Have we or the partner been compromised somehow ?
i'm really interested in understanding because it is the best phishing i've seen so far lmao ! if you're not attentive and don't check the mailing adress it's really easy to get caught.

thanks bye