- Joined
- Dec 30, 2024
- Messages
- 326
- Reaction score
- 200
- Points
- 62
- Website
- blackhatpakistan.net
- Points
- 758
- USD
- 758
Business email compromise explained end to end: mailbox access, thread hijacking, invoice redirection, wire instruction swaps and the mule layer that receives - the highest per-incident loss category in fraud reporting, and the structure behind it. No malware, no card data - just correspondence and timing.
TL;DR - No malware at all - mailbox access plus thread hijack plus timing converts.
ACCESS LAYER
Once inside, the reconnaissance pass is the whole operation''s foundation: invoice history, vendor lists, payment instruction documents, executive travel calendar, signature format, approval thresholds.
THE PLAYBOOKS
Thread hijacking converts best because every participant already trusts the thread - the request just changes rails mid-conversation.
THE WIRE STEP
PERSISTENCE PLANTED
Mailbox rules are the quiet part: inbox rules forwarding payment-related mail to folders the victim never opens, deletion rules on confirmations from banks, delegated-access grants for continued entry after password reset. Cleanup crews skip this step; professional operations treat rule installation as mandatory before first contact.
DETECTION SURFACE
Correspondence fraud dies on audit visibility and callback discipline - which is why operations target organizations with thin IT review and heavy payment volume.
★ MEMBER BONUS — FIELD CHEAT SHEET
Hit reply to unlock the sheet - takes five seconds.
Post BEC observations below - variant, what the org''s callback caught or missed, and how far the wire got before recall.
— RELATED GUIDES —
TL;DR - No malware at all - mailbox access plus thread hijack plus timing converts.
ACCESS LAYER
- Credential stuffing and reverse proxy capture against corporate identity (relay kits handle MFA)
- Delegate access granted through phishing consent - mailbox shared without password ever moving
- Compromised webmail sessions bought from access markets
Once inside, the reconnaissance pass is the whole operation''s foundation: invoice history, vendor lists, payment instruction documents, executive travel calendar, signature format, approval thresholds.
THE PLAYBOOKS
| Variant | Mechanics |
| Account compromise (BEC-A) | Vendor or executive mailbox used directly; reply into real threads |
| Domain spoof / lookalike (BEC-B) | Lookalike domain, near-identical address, new "vendor" thread |
| Thread hijack | Attacker replies inside genuine multi-party conversation - highest trust, best conversion |
| CEO-to-finance | Urgency directive from executive identity: confidential transfer, vendor must be paid now |
Thread hijacking converts best because every participant already trusts the thread - the request just changes rails mid-conversation.
THE WIRE STEP
- Payment instruction arrives - new bank details, urgent, confidentiality pretext
- First test transfer smaller; full amount follows when the smaller one clears
- Receiving mules move funds within 24-48 hours through the standard tier structure (mule economics)
- Wire recall requests and fraud holds arrive after the money has already hopped twice
PERSISTENCE PLANTED
Mailbox rules are the quiet part: inbox rules forwarding payment-related mail to folders the victim never opens, deletion rules on confirmations from banks, delegated-access grants for continued entry after password reset. Cleanup crews skip this step; professional operations treat rule installation as mandatory before first contact.
DETECTION SURFACE
- Rule creation events and delegate grants in audit logs - the earliest reliable signal
- New-domain registration age against vendor-change requests
- Out-of-pattern wire velocity and beneficiary novelty at the receiving bank
- Timing tells: instruction changes landing on Friday afternoons and holidays are the standard script
Correspondence fraud dies on audit visibility and callback discipline - which is why operations target organizations with thin IT review and heavy payment volume.
★ MEMBER BONUS — FIELD CHEAT SHEET
Hit reply to unlock the sheet - takes five seconds.
Post BEC observations below - variant, what the org''s callback caught or missed, and how far the wire got before recall.
— RELATED GUIDES —
- 3DS Explained 2026
- Money Mule Networks Explained
- Stealer Log Cashout Guide
- Virtual Credit Cards Guide
- Fraud Detection Signals 2026
- Gift Card Resale 2026
- Carding OPSEC 2026
- Chargebacks Explained
- Credential Stuffing Guide
- Crypto Off-Ramps 2026
- Physical Goods Drops
- Account Takeover Playbook
- Prepaid Card Strategy
- Telegram Bots Guide
- Data Freshness Guide
- EMV Chip Data Explained
- Synthetic Identities Guide
- Card Skimmer Infrastructure
- Reverse Proxy Phishing
- SIM Swap Operations
- Crypto Drainer Kits
- Fake ID Manufacturing
- Dark Web Vendor Opsec
- POS RAM Scrappers
- Cashout Methods Explained 2026
- CVV vs Fullz vs Logs
- BIN Guide 2026
- What Makes a Site Cardable
- How CC Checkers Actually Work
Last edited: