As the world becomes more and more connected, and digital technologies continue to evolve, email remains a critical tool for communications both for individuals and for commercial use. Email security has become more and more important, with a significant rise in digital attacks of late targeting critical communication within email. One such threat that has been growing in popularity is the email bomb.
What is an email bomb?
In simple terms, an email bomb typically involves subscribing victims to a large number of newsletter and subscription services. Each of these sends its own email notification to the victim making email triage for legitimate emails very difficult.
But why should I care?
Email bombs are commonly used to obfuscate more nefarious activity. For example, it is harder to spot emails about login attempts or changes to your MFA settings if these are buried amongst hundreds or thousands of emails that have bombed your inbox.
More recently, attackers have used email bombs alongside lures on Microsoft Teams, phone calls, etc. whereby the attacker will impersonate IT Support to gain access to the victim's device to conduct further attack. Microsoft has a great write-up of an example of this here: https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/
Protecting against email bombs
Microsoft Defender for Office have released a new solution to help protect against the sudden rise of email bombing attacks. One such feature is limiting the influx of emails to a mailbox. By analysing a baseline of message volumes across different sources and time intervals, a new detection can then leverage historical patterns of the sender and any signals that may indicate spam content. These messages are then sent to the Junk folder of Outlook, instead of the inbox.
Advanced hunting
An advanced hunting query can be used to detect mail bombing attacks. This can then be used to create a custom detection to alert the SOC team whenever a mail bombing attack is detected. For example:
EmailEvents
| where Timestamp > ago(1d)
| where DetectionMethods contains "Mail bombing"
| project Timestamp, NetworkMessageId, SenderFromAddress, Subject, ReportIdIn the portal
SOC analysts can now view the new Detection technology as Mail bombing within the following surfaces: Threat Explorer, Email entity page and Advanced Hunting empowering them to investigate, filter and hunt for threats related to mail bombing.