• Blackhat Pakistan — Ethical Hacking, Hacking Tools & Cybersecurity Tutorials

BEC Wire Fraud Chain

Blackhatpakistan

Administrator
Staff member
Joined
Dec 30, 2024
Messages
326
Reaction score
202
Points
62
Website
blackhatpakistan.net
Points
758
USD
758
Business email compromise explained end to end: mailbox access, thread hijacking, invoice redirection, wire instruction swaps and the mule layer that receives - the highest per-incident loss category in fraud reporting, and the structure behind it. No malware, no card data - just correspondence and timing.

TL;DR - No malware at all - mailbox access plus thread hijack plus timing converts.

ACCESS LAYER

  • Credential stuffing and reverse proxy capture against corporate identity (relay kits handle MFA)
  • Delegate access granted through phishing consent - mailbox shared without password ever moving
  • Compromised webmail sessions bought from access markets

Once inside, the reconnaissance pass is the whole operation''s foundation: invoice history, vendor lists, payment instruction documents, executive travel calendar, signature format, approval thresholds.

THE PLAYBOOKS

VariantMechanics
Account compromise (BEC-A)Vendor or executive mailbox used directly; reply into real threads
Domain spoof / lookalike (BEC-B)Lookalike domain, near-identical address, new "vendor" thread
Thread hijackAttacker replies inside genuine multi-party conversation - highest trust, best conversion
CEO-to-financeUrgency directive from executive identity: confidential transfer, vendor must be paid now

Thread hijacking converts best because every participant already trusts the thread - the request just changes rails mid-conversation.

THE WIRE STEP

  • Payment instruction arrives - new bank details, urgent, confidentiality pretext
  • First test transfer smaller; full amount follows when the smaller one clears
  • Receiving mules move funds within 24-48 hours through the standard tier structure (mule economics)
  • Wire recall requests and fraud holds arrive after the money has already hopped twice

PERSISTENCE PLANTED

Mailbox rules are the quiet part: inbox rules forwarding payment-related mail to folders the victim never opens, deletion rules on confirmations from banks, delegated-access grants for continued entry after password reset. Cleanup crews skip this step; professional operations treat rule installation as mandatory before first contact.

DETECTION SURFACE

  • Rule creation events and delegate grants in audit logs - the earliest reliable signal
  • New-domain registration age against vendor-change requests
  • Out-of-pattern wire velocity and beneficiary novelty at the receiving bank
  • Timing tells: instruction changes landing on Friday afternoons and holidays are the standard script

Correspondence fraud dies on audit visibility and callback discipline - which is why operations target organizations with thin IT review and heavy payment volume.

★ MEMBER BONUS — FIELD CHEAT SHEET

Hit reply to unlock the sheet - takes five seconds.

Post BEC observations below - variant, what the org''s callback caught or missed, and how far the wire got before recall.

— RELATED GUIDES —
 
Last edited:
Threads
997Threads
Messages
2,003Messages
Members
3,659Members
Latest member
ablahukuLatest member
Top