Detection of O365 Email Receive and Hard Delete Takeover Behavior
Threat actors are suppressing evidence of account compromise by receiving and then hard-deleting emails related to sensitive banking, payroll, or credential changes within Office 365 environments.
What's new
- 1. added coverage for Office 365 Sep 29, 10:11 via splunk-escu
This threat involves the unauthorized manipulation of Microsoft Office 365 mailboxes by threat actors to facilitate financial fraud or maintain persistence. After gaining access to a user account, adversaries target sensitive incoming communications such as banking notifications, direct deposit updates, MFA requests, or password reset alerts. To avoid detection by the account owner, the actor performs a hard delete of these messages from the 'Sent Items' or 'Recoverable Items' folders. This behavior is a critical indicator of account takeover (ATO) and is often associated with payroll redirection scams. Defenders should monitor for the correlation between incoming messages containing sensitive keywords and subsequent mailbox management activities that bypass standard trash bin recovery paths.
Attack Chain
- Attacker gains initial access to a user account (e.g., via phishing, session token theft, or credential stuffing).
- Attacker configures mailbox access to monitor for sensitive communications.
- Attacker intercepts or triggers an email related to payroll, MFA, or account recovery keywords.
- Attacker performs the malicious action (e.g., redirects direct deposit or modifies security settings).
- Attacker locates the confirmation or notification email within the inbox.
- Attacker initiates an Exchange 'HardDelete' operation to remove the email from the 'Recoverable Items' or 'Sent Items' folders.
- Attacker successfully obscures evidence of the unauthorized change, delaying victim detection.
Impact
Successful exploitation allows threat actors to perform unauthorized financial transactions, such as redirecting payroll payments to attacker-controlled accounts. The act of hard-deleting messages removes forensic evidence of the compromise, complicating incident response and recovery efforts.
Recommendation
Prioritize monitoring for anomalous mailbox operations that attempt to purge sensitive audit trails.
- Implement logging for 'HardDelete' operations in the Office 365 Universal Audit Log to detect potential evidence tampering.
- Correlate message trace data with mailbox management activity logs to identify the rapid succession of message receipt and deletion.
- Investigate user accounts flagged by these patterns for signs of unauthorized access, such as unexpected IP addresses or unusual User-Agent strings.
Immediate actions
Enable Office 365 Universal Audit Log ingestion for all Exchange mailbox activity.
Threat Hunt
Search for 'HardDelete' operations in the 'Recoverable Items' folder targeting users with recent sensitive emails.
Data: Office 365 Universal Audit Log