Malicious Usage of eM Client In Business Email Compromise – Syne's Cyber Corner
If you’ve found your way to this article, it’s likely because you have found a suspicious application content for eM Client. This is an application that is similar in it’s usage to PERFECTDATA SOFTWARE, but is also distinct. While the exact reason why threat actors use that application is not conclusively known, my examination of it’s behavior has uncovered some features that make it useful for threat actors during a business email compromise. Unlike my investigation into PDS, I did not have to search hard to find eM Client. Simply Google the name, and you will see eM Client’s website as the first result. Once I found the application I downloaded and installed it into a virtual machine running Windows 10. For the accounts, I used two accounts and one shared mailbox, all from my Honeypot Developer Tenant. I describe eM Client as an alternative mail access program. It connects using Exchange Web Services, which is an API that allows non-Microsoft applications to integrate with Exchange O
Posted in Azure AD Featured Forensics Incident Response Office 365 Posted by By syne0 January 31, 2024 No Comments If you’ve found your way to this article, it’s likely because you have found a suspicious application content for eM Client. This is an application that is similar in it’s usage to PERFECTDATA SOFTWARE , but is also distinct. While the exact reason why threat actors use that application is not conclusively known, my examination of it’s behavior has uncovered some features that make it useful for threat actors during a business email compromise. Methodology
Explore this link on the map →saved by
related reading
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Email Compromise To Mass Phishing Campaigndarktrace.com
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- PerfectData Software Abuse and Account Takeover Risksdarktrace.com
- Legacy authentication: The curious case of BAV2ROPCredcanary.com
- When MFA isn’t an option: The legacy of ROPC | Red Canaryredcanary.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Best Email Management Software 2026 | TrustRadiustrustradius.com