Skip to main content
The One-Letter Vendor: Typosquat Invoice Thread Hijack operation cover
IntermediateEmailSIEMPRO

The One-Letter Vendor: Typosquat Invoice Thread Hijack

An accounts-payable team received what looked like a routine reply on an open invoice thread from a trusted supplier. It passed every mail gateway, because the From domain authenticated perfectly. The catch was four mailboxes in the CC field on a domain one letter off the real vendor, quietly hijacking the thread to redirect a six-figure payment to an attacker account. No malware, no account takeover, just mail authentication's blind spot. Work the headers, authentication results, and message traces to reconstruct the vendor-email-compromise fraud.

40m
7 tasks
50 points
Pro

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Incident brief

0

Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.

2

Identify the look-alike domain

40

The whole intrusion hinges on one registered domain that almost matches a real supplier. Identify the domain the operator controlled.

Hint available
3

Explain why the gateways passed it

35

Every enterprise mail gateway delivered the message clean. Identify the authentication result that let it through.

Hint available
4

Name the hijacked invoice thread's target

35

The operator was after one specific outstanding payment. Identify the open invoice number they tried to redirect.

Hint available
5

Recover the attachment indicator

35

Pin down a huntable file indicator for the fraudulent invoice PDFs. Provide the MD5 of the 30092 attachment.

Hint available
6

Trace the injecting host

35

Although authentication passed, the message did not originate from the vendor's real mail path. Identify the originating sending host.

Hint available
7

Classify the impersonation

35

Name what the operator was fundamentally doing to the finance team. Classify the technique with its MITRE ATT&CK ID.

Hint available

7 tasks · 215 points total

Training Tools

Skills You'll Build

Investigate realistic security alerts
Email log analysis
SIEM log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Intermediate

Requires foundational alert triage skills. Multiple data sources to correlate.

Prerequisites

  • Basic understanding of security alerts
  • Familiarity with Email concepts
  • Familiarity with SIEM concepts

Ready to investigate?

More Operations

View all
BeginnerSIEMFirewall

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m25 pts
BeginnerEmailXDR

OneNote Attachment to RAT: A Guided First Investigation

A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.

15m25 pts
BeginnerSIEMFirewall

Hijacked Discord Invite to ClickFix Loader: Tracing the Lure

A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.

15m25 pts