
The One-Letter Vendor: Typosquat Invoice Thread Hijack
An accounts-payable team received what looked like a routine reply on an open invoice thread from a trusted supplier. It passed every mail gateway, because the From domain authenticated perfectly. The catch was four mailboxes in the CC field on a domain one letter off the real vendor, quietly hijacking the thread to redirect a six-figure payment to an attacker account. No malware, no account takeover, just mail authentication's blind spot. Work the headers, authentication results, and message traces to reconstruct the vendor-email-compromise fraud.
Start this operation
Investigation Tasks
Complete each task by investigating alerts and submitting your findings.
Incident brief
0Orient yourself before pivoting into the data. This is a no-answer briefing checkpoint.
Identify the look-alike domain
40The whole intrusion hinges on one registered domain that almost matches a real supplier. Identify the domain the operator controlled.
Explain why the gateways passed it
35Every enterprise mail gateway delivered the message clean. Identify the authentication result that let it through.
Name the hijacked invoice thread's target
35The operator was after one specific outstanding payment. Identify the open invoice number they tried to redirect.
Recover the attachment indicator
35Pin down a huntable file indicator for the fraudulent invoice PDFs. Provide the MD5 of the 30092 attachment.
Trace the injecting host
35Although authentication passed, the message did not originate from the vendor's real mail path. Identify the originating sending host.
Classify the impersonation
35Name what the operator was fundamentally doing to the finance team. Classify the technique with its MITRE ATT&CK ID.
7 tasks · 215 points total
Training Tools
Skills You'll Build
Requires foundational alert triage skills. Multiple data sources to correlate.
Prerequisites
- Basic understanding of security alerts
- Familiarity with Email concepts
- Familiarity with SIEM concepts
Ready to investigate?
More Operations
View allThe Template That Read the Disk
The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.
OneNote Attachment to RAT: A Guided First Investigation
A logistics contracts employee at Glacierline Freight opens an attachment that arrived in her inbox and clicks a button inside it. Minutes later her workstation is running something that appears on no software inventory and is talking to a host that no business process uses. Walk the email gateway records, the file artifacts and the endpoint process tree one step at a time, and work out for yourself which message carried the delivery, what landed on disk, and what ran.
Hijacked Discord Invite to ClickFix Loader: Tracing the Lure
A finance analyst at Halcyon Wealth Partners followed a recycled Discord invite that quietly redirected the browser to a fake verification page. They did what the page asked, and inside the hour the workstation was running a remote-access trojan alongside an info-stealer that shipped browser data straight out of the building. Walk the proxy, endpoint and firewall evidence step by step to trace the lure, the loader, the C2 beacon and the data theft.