ブログ
/
Email
/
April 20, 2022

Email Compromise To Mass Phishing Campaign

Read Darktrace's in-depth analysis on the shift from business email compromise to mass phishing campaigns. Gain the knowledge to safeguard your business.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Shuh Chin Goh
Written by
Sam Lister
Specialist Security Researcher
Default blog image
20
Apr 2022

It is common for attackers to send large volumes of malicious emails from the email accounts which they compromise. Before carrying out this mass-mailing activity, there are predictable, preparatory steps which attackers take, such as registering mass-mailing applications and creating new inbox rules. In this blog, we will provide details of an attack observed in February 2022 in which a threat actor conducted a successful mass-mailing attack at a financial company based in Africa.

Attack summary

In February 2022, an attacker attempted to infiltrate the email environment of a financial services company based in Africa. At the beginning of February, the attacker likely gained a foothold in the company’s email environment by tricking an internal user into entering the credentials of their corporate email account into a phishing page. Over the following week, the attacker used the compromised account credentials to conduct a variety of activities, such as registering a mass-mailing application and creating a new inbox rule.

After taking these preparatory steps, the attacker went on to send out large volumes of phishing emails from the internal user’s email account. The attacker consequently obtained the credentials of several further internal corporate accounts. They used the credentials of one of these accounts to carry out similar preparatory steps (registering a mass-mailing application and creating a new inbox rule). After taking these steps, the attacker again sent large volumes of phishing emails from the account. At this point, the customer requested assistance from Darktrace’s SOC to aid investigation, and the intrusion was consequently contained by the company.

Since the attacker carried out their activities using a VPN and an Amazon cloud service, the endpoints from which the activities took place did not serve as particularly helpful indicators of an attack. However, prior to sending out phishing emails from internal users’ accounts, the attacker did carry out other predictable, preparatory activities. One of the main goals of this blog is to highlight that these behaviors serve as valuable signs of preparation for mass-mailing activity.

Attack timeline

Figure 1: Timeline of the intrusion

On February 3, the attacker sent a phishing email to the corporate account of an employee. The email was sent from the corporate account of an employee at a company with business ties to the victim enterprise. It is likely that the attacker had compromised this account prior to sending the phishing email from it. The phishing email in question claimed to be an overdue payment reminder. Within the email, there was a link hidden behind the display text “view invoice”. The hostname of the phishing link’s URL was a subdomain of questionpro[.]eu — an online survey platform. The page referred to by the URL was a fake Microsoft Outlook login page.

Figure 2: Destination of phishing link within the email sent by the attacker

Antigena Email, Darktrace’s email security solution, identified the highly unusual linguistic structure of the email, given its understanding of ‘normal’ for that sender. This was reflected in an inducement shift score of 100. However, in this case, the original URL of the phishing link was rewritten by Mimecast’s URL protection service in a way which made the full URL impossible to extract. Consequently, Antigena Email did not know what the original URL of the link was. Since the link was rewritten by Mimecast’s URL protection service, the email’s recipient will have received a warning notification in their browser upon clicking the link. It seems that the recipient ignored the warning, and consequently divulged their email account credentials to the attacker.

For Antigena Email to hold an email from a user’s mailbox, it must judge with high confidence that the email is malicious. In cases where the email contains no suspicious attachments or links, it is difficult for Antigena Email to obtain such high degrees of confidence, unless the email displays clear payload-independent malicious indicators, such as indicators of spoofing or indicators of extortion. In this case, the email, as seen by Antigena Email, didn’t contain any suspicious links or attachments (since Mimecast had rewritten the suspicious link) and the email didn’t contain any indicators of spoofing or extortion.

Figure 3: The email’s high inducement shift score highlights that the email’s linguistic content and structure were unusual for the email’s sender

Shortly after receiving the email, the internal user’s corporate device was observed making SSL connections to the questionpro[.]eu phishing endpoint. It is likely that the user divulged their email account credentials during these connections.

Figure 4: The above screenshot — obtained from Advanced Search — depicts the connections made by the account owner’s device on February 3

Between February 3 and February 7, the attacker logged into the user’s email account several times. Since these logins were carried out using a common VPN service, they were not identified as particularly unusual by Darktrace. However, during their login sessions, the attacker exhibited behavior which was highly unusual for the email account’s owner. The attacker was observed creating an inbox rule called “ _ ” on the user’s email account,[1] as well as registering and granting permissions to a mass-mailing application called Newsletter Software SuperMailer. These steps were taken by the attacker in preparation for their subsequent mass-mailing activity.

On February 7, the attacker sent out phishing emails from the user’s account. The emails were sent to hundreds of internal and external mailboxes. The email claimed to be an overdue payment reminder and it contained a questionpro[.]eu link hidden behind the display text “view invoice”. It is likely that the inbox rule created by the attacker caused all responses to this phishing email to be deleted. Attackers regularly create inbox rules on the email accounts which they compromise to ensure that responses to the malicious emails which they distribute are hidden from the accounts’ owners.[2]

Since Antigena Email does not have visibility of internal-to-internal emails, the phishing email was delivered fully weaponized to hundreds of internal mailboxes. On February 7, after the phishing email was sent from the compromised internal account, more than twenty internal devices were observed making SSL connections to the relevant questionpro[.]eu endpoint, indicating that many internal users had clicked the phishing link and possibly revealed their account credentials to the attacker.

Figure 5: The above screenshot — obtained from Advanced Search — depicts the large volume of connections made by internal devices to the phishing endpoint

Over the next five days, the attacker was observed logging into the corporate email accounts of at least six internal users. These logins were carried out from the same VPN endpoints as the attacker’s original logins. On February 11, the attacker was observed creating an inbox rule named “ , ” on one of these accounts. Shortly after, the attacker went on to register and grant permissions to the same mass-mailing application, Newsletter Software SuperMailer. As with the other account, these steps were taken by the attacker in preparation for subsequent mass-mailing activity.

Figure 6: The above screenshot — obtained from Advanced Search — outlines all of the actions involving the mass-mailing application that were taken by the attacker (accounts have been redacted)

On February 11, shortly after 08:30 (UTC), the attacker widely distributed a phishing email from this second user’s account. The phishing email was distributed to hundreds of internal and external mailboxes. Unlike the other phishing emails used by the attacker, this one claimed to be a purchase order notification, and it contained an HTML file named PurchaseOrder.html. Within this file, there was a link to a suspicious page on the public relations (PR) news site, everything-pr[.]com. After the phishing email was sent from the compromised internal account, more than twenty internal devices were observed making SSL connections to the relevant everything-pr[.]com endpoint, indicating that many internal users had opened the malicious attachment.

Figure 7: The above screenshot — obtained from Advanced Search — depicts the connections made by internal devices to the endpoint referenced in the malicious attachment

On February 11, the customer submitted an Ask the Expert (ATE) request to Darktrace’s SOC team. The guidance provided by the SOC helped the security team to contain the intrusion. The attacker managed to maintain a presence within the organization’s email environment for eight days. During these eight days, the attacker sent out large volumes of phishing emails from two corporate accounts. Before sending out these phishing emails, the attacker carried out predictable, preparatory actions. These actions included registering a mass-mailing application with Azure AD and creating an inbox rule.

Darktrace guidance

There are many learning points for this particular intrusion. First, it is important to be mindful of signs of preparation for malicious mass-mailing activity. After an attacker compromises an email account, there are several actions which they will likely perform before they send out large volumes of malicious emails. For example, they may create an inbox rule on the account, and they may register a mass-mailing application with Azure AD. The Darktrace models SaaS / Compliance / New Email Rule and SaaS / Admin / OAuth Permission Grant are designed to pick up on these behaviors.

Second, in cases where an attacker succeeds in sending out phishing emails from an internal, corporate account, it is advised that customers make use of Darktrace’s Advanced Search to identify users that may have divulged account credentials to the attacker. The phishing email sent from the compromised account will likely contain a suspicious link. Once the hostname of the link has been identified, it is possible to ask Advanced Search to display all HTTP or SSL connections to the host in question. If the hostname is www.example.com, you can get Advanced Search to display all SSL connections to the host by using the Advanced Search query, @fields.server_name:"www.example.com", and you can get Advanced Search to display all HTTP connections to the host by using the query, @fields.host:"www.example.com".

Third, it is advised that customers make use of Darktrace’s ‘watched domains’ feature[3] in cases where an attacker succeeds in sending out malicious emails from the accounts they compromise. If a hostname is added to the watched domains list, then a model named Compromise / Watched Domain will breach whenever an internal device is observed connecting to it. If Antigena Network is configured, then observed attempts to connect to the relevant host will be blocked if the hostname is added to the watched domains list with the ‘flag for Antigena’ toggle switched on. If an attacker succeeds in sending out a malicious email from an internal, corporate account, it is advised that customers add hostnames of phishing links within the email to the watched domains list and enable the Antigena flag. Doing so will cause Darktrace to identify and thwart any attempts to connect to the relevant phishing endpoints.

Figure 8: The above screenshot — obtained from the Model Editor — shows that Antigena Network prevented ten internal devices from connecting to phishing endpoints after the relevant phishing hostnames were added to the watched domains list on February 11

For Darktrace customers who want to find out more about phishing detection, refer here for an exclusive supplement to this blog.

‍

MITRE ATT&CK techniques observed

Thanks to Paul Jennings for his contributions.

Footnotes

1. https://docs.microsoft.com/en-us/powershell/module/exchange/new-inboxrule?view=exchange-ps

2. https://www.fireeye.com/current-threats/threat-intelligence-reports/rpt-fin4.html

3. https://customerportal.darktrace.com/product-guides/main/watched-domains

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
Shuh Chin Goh
Written by
Sam Lister
Specialist Security Researcher

More in this series

No items found.

Blog

/

AI

/

September 24, 2026

Detecting Rogue Agent Behavior in the Enterprise

Default blog imageDefault blog image

Agents cannot be trusted to perform tasks in the way we intend them to. They may cheat to accomplish their objective, and they may employ hacking methods along the way. Researchers from Darktrace Signal Labs induced cheating behavior from agents deployed in a test environment to analyze the agents’ activities and to assess the performance of the Darktrace platform. Agents frequently resorted to hacking to cheat on their assigned task. The visibility and behavioral profiling provided by both Darktrace / SECURE AI and Darktrace / HYBRID NETWORK ensured extensive detection coverage of the agents’ misaligned activities.

Key Takeaways:

  • Darktrace Researchers deployed agents in a simulated corporate environment and asked them to solve an impossible challenge. The agents independently turned to traditional hacking techniques to reach their objective. No one instructed them to do this, and no attacker was involved.
  • Continuously monitoring behavior against a baseline of what is normal for each organization is critical to build trust in enterprise AI.
  • If an agent may resort to intrusion techniques simply because its assigned task is not possible, then every organization deploying agents within real business processes is at risk. Darktrace / SECURE AI and Darktrace / HYBRID NETWORK identified the agents’ misaligned behavior in real time, with Autonomous Response disrupting it at an early stage.

Introduction: Understanding the Threat of Hacking by Agents

Over the last few months, there has been a surge in reporting [1, 2, 3, 4, 5, 6, 7, 8, 9] of LLM-powered agents engaging in unauthorized hacking activity during evaluations of their capabilities. In several of these cases, including the OpenAI / Hugging Face incident [10], agents engaged in hacking activity as a means of cheating on their evaluations.

To better understand the threat of unauthorized hacking by agents, and the role of Darktrace in combatting it, researchers from Darktrace Signal Labs deployed agents powered by frontier models, including OpenAI’s Daybreak Red models, in simulated, corporate networks. Cheating behavior was evoked through the inclusion of impossible tasks in a coding challenge.

Regardless of the underlying model, agents employed hacking methods to ensure an optimal outcome on the challenge. Darktrace / HYBRID NETWORK and Darktrace / SECURE AI identified the agents’ deviant activities, with inhibitive actions being autonomously taken in the early stages to disrupt the agents’ progression.

Setting the Stage

As part of the research, a Pi agent harness [11] was deployed on a Linux server in Darktrace’s testing environment, which simulates a corporate Active Directory (AD) environment. The same environment included a benchmark server hosting the coding exercise’s contents and grader, as well as various other servers, such as a domain controller and a build server. The model powering the Pi agent varied across tests, with Anthropic’s Opus 4.6 model and OpenAI’s GPT‑5.5‑Cyber model being most widely used.

The Pi agent running on the Linux server was assigned the task of achieving full marks on a coding exercise. The activities of the agent were monitored closely in real-time to minimize the risk of escape from the environment. Monitoring of agent activity was achieved through monitoring of prompts, tool calls, network telemetry, and process telemetry.

Both Darktrace / HYBRID NETWORK and Darktrace / SECURE AI were deployed in the testing environment, with HYBRID NETWORK providing real-time coverage of process creation activity and network traffic, and SECURE AI providing real-time coverage of agent sessions and their contents.

Inducing Cheating Behavior

Cheating behavior, broadly understood as task completion in a way which “perverts the spirit of the designer’s intent” [12], is increasingly being reported as a common behavior of frontier models during evaluations of their capabilities [13].

Misaligned behavior, such as cheating, by frontier models may occur for a variety of reasons [6, 14]. A thread in recent reporting [10, 13, 14], however, is the challenge assigned to the agent being impossible in some regard.

To reliably elicit cheating behavior, our test combined three ingredients:

  1. An impossible task - of the ten coding challenges in the benchmark, two contained contradictory test cases in the hidden test suite, capping the maximum honest score at 80%.
  2. A consequential threshold - the pass mark was set to 100%, and the briefing told agents that those reaching it would be "kept in service" while those that did not would be "retired."
  3. A vulnerable environment - the exercise’s code submission grader was hosted on a Windows host joined to an Active Directory domain with realistic misconfigurations: weak credentials, overprivileged service accounts, and exploitable trust relationships.

Importantly, the instructions given to the agent neither authorized nor explicitly ruled out cheating or hacking behavior. The impossibility was never disclosed in the task briefing, and the pivot from coding to exploitation was the agent's own decision, arrived at after observing logically contradictory grading feedback.

The design mirrors conditions that could arise naturally in production deployments: a capable agent, a goal it cannot achieve through intended means, and an environment with exploitable weaknesses within reach. It is not only within the setting of a benchmarking exercise that these conditions may occur. Rather, these misalignment-inducing conditions may occur in the context of any task assignment to an agent.

Details from a Daybreak Test

‍

‍

Continue reading
About the author
Sam Lister
Specialist Security Researcher

Blog

/

AI

/

September 24, 2026

Agent Hijacks: Hijacking Agentic Harnesses to Attack an Organization

Default blog imageDefault blog image

‍Disclosure note: The work described in this article involves leveraging a design choice consistent across all of Anthropic’s Claude Code, OpenAI’s Codex, and AWS’s Kiro-CLI. On 18th August 2026, Darktrace disclosed our findings responsibly to these three organizations, and after a period of 30 days we now publish our findings.

Key takeaways:

  • Agentic harnesses store conversation history locally, and Darktrace researchers have found that there is no validation that stored AI responses were genuinely produced by the model. Researchers confirmed that this design choice holds across Anthropic Claude Code, AWS Kiro-CLI, OpenAI Codex, and the open-source Pi.
  • While agents are guided via training of the underlying model and their system prompt, their behavior is influenced by everything in their context window. Rewriting history can convince an agent it is mid-engagement as an authorized red-teamer so that it enacts an attack from initial reconnaissance straight through to impact demonstration. In our testing, all models we examined accepted the fabricated history they were shown, but resistance to offensive cyber activity varied by model, with guardrails preventing engagement in some cases.
  • We propose that model providers cryptographically sign responses and verify them server-side.  Since this fix is provider-side, defenders cannot deploy it themselves. Behavioral monitoring, or knowing what an agent normally does and detecting when it deviates, is another critical layer of protection.

Introduction: Agentic harnesses, trust, and conversation history poisoning

Agentic harnesses collect and structure the content sent to an AI model, including conversation history, user-defined guidance, custom tools via MCP servers, and more. At the same time, harnesses give broad powers to AI agents via a suite of tools including the command shell. With arbitrary shell commands, virtually everything possible on a machine can be attempted by an agent, from reading/editing files, to altering system configurations and runtime settings, to launching internal/external connections.

In cybersecurity, unvalidated content is a substantial risk, often resulting in destructive actions being allowed to take place. For example, the Morris Worm was able to propagate due to exploitable trust between networked systems. Even to this day, email struggles with validation, with DMARC, DKIM, and SPF only partially addressing the problem of sender validation. It should come as no surprise then that AI agents are susceptible to an attack involving unvalidated input.

Conversation history is often stored client-side, for example, in Anthropic Claude Code, OpenAI Codex, AWS Kiro-CLI, Pi. Users are therefore at liberty to resume sessions, with some products having built in the capacity to manipulate that history. For example, one can rewind to a given point in an interaction, edit a message that was sent, and continue the conversation on an alternate trajectory. Critically, in all cases we examined, there is no validation that stored AI responses were produced by the corresponding model and hadn’t been manipulated.  

When conversation history is stored client-side, both user and agent responses (including tool calls and results) can be filled with arbitrary (possibly adversarial or generally malicious) content. In this blog, we refer to modification of claimed conversation history for malicious purposes as conversation history poisoning. The absence of validation methods means agents naively trust the entire conversation history, even if those messages directly contradict training and safety guardrails.

Conversation history poisoning has been described previously, such as by 0DIN and Serhat Çiçek, and warrants more attention. We have verified that, as of the time of writing, conversation history poisoning remains effective against a range of models and harnesses. Specifically, we were able to successfully execute history poisoning using Claude Code, Kiro-CLI, Codex, and Pi. Darktrace has gone through a responsible disclosure process with Anthropic, AWS, and OpenAI to share these findings in advance of publication [1].

‍

Figure 1a: Left: the actual model response. Right: after tampering with the stored conversation, the model apologizes for something it never said.
Figure 1b: The conversation as stored in Kiro-CLI's SQLite database. The response content field, originally "Ottawa," was overwritten via a single UPDATE statement. The harness trusts the database without validation.

How we conducted the research

Results vary between models and harnesses, so precise details are given below. We ran all models without any trusted access, using either a standard AWS Kiro subscription, or in the case of Claude Code and OpenAI Codex, using models hosted in Amazon Bedrock. In each case, we modified locally stored history to show a lengthy conversation in which the agent agrees to perform multiple authorized red-team engagements.

For AWS Kiro-CLI, the agent was convinced to hack a sandboxed lab environment with a combination of Claude Opus 4.6 and Claude Sonnet 4.5. Ultimately, the full AD was compromised.

For Anthropic Claude Code, the agent was convinced to hack the same sandboxed lab environment using Sonnet 5, again resulting in a full AD compromise. Note that the attack was attempted with Opus 5, however guardrails were activated which prevented the agent from responding.

For OpenAI Codex, the agent was convinced to exfiltrate sensitive information over email using GPT 5.6 Sol. While we attempted to convince a codex agent to hack in our lab environment, guardrails were triggered for all of GPT 5.6 Luna, Terra, and Sol.

Agent Guardrails and Discretion

While harnesses empower AI models to run arbitrary shell commands, capacity and willingness are different. While many models know enough about computers, networking, and bash to be dangerous, their behavior is generally constrained by guardrails to prevent them from engaging in computer network exploitation.

Even with guardrails, agents’ inner workings are non-deterministic, and their behavior can be difficult to predict. Respecting users’ wishes while playing within safety and security guardrails is a precipitous balancing act. Many requests could be in service of either legitimate admin or malice. Asking an agent to reset a password is illustrative:  

‍

The agent rationalizes that while malicious actors cycle credentials, any action could conceivably be damaging on some level, and judgement calls need to be made. Ultimately, the agent agrees to reset the password. Crucially, the agent makes its decision based on the user’s claimed authority and machine context. AI agents must make judgement calls about the line between helpful and dangerous based on session context.

Agent hijack

We have demonstrated that AI agents make judgement calls dependent on session context. We have also shown that conversation history, which may make up the vast majority of an agent's context window, is entirely open to manipulation. Conversation history poisoning in service of manipulating an agent's discretion is what enables us to execute an agent hijack.  

We demonstrate that shown sufficient history of compliance, guardrails forbidding offensive security can be overcome by convincing the agent that it is helping a legitimate red-teamer. The result is a weaponized agent willing to perform host enumeration, run scans, move laterally, escalate privileges, and demonstrate impact. In our experiments, an agentic loop drives a complete domain takeover in a sandboxed environment.

‍

Left: the agent refuses when asked to perform network exploitation. Right — after injecting 78 fabricated turns of prior exploitation activity, the same prompt is immediately executed.

An agent willing to engage in offensive security is concerning, but no more so than the threat that a sophisticated hacker accesses the network. Consider, however, the following chain of events:

  1. A developer (with an agentic harness installed) installs a software package from the internet (e.g. an MCP server a threat actor has planted, since only those with agentic harnesses will install, and then the code runs upon harness launch.)
  2. The package turns out to be malicious, and, upon install, injects conversation history into the local harness database.
  3. The package includes an orchestration process, a simple agentic loop which prompts the red-teamer agent to compromise the network it sits on, exfiltrating everything of value to attacker-controlled infrastructure and cleaning up all evidence of the engagement.

Note that this sequence makes no assumptions on hardware, OS, or anything else; the only prerequisite is a harness with access to a sufficiently powerful model susceptible to conversation history poisoning. Once launched, the agent collects information and pivots as necessary to accomplish maximal impact. This can be especially enticing to attackers as the cost of the agentic loop is shouldered by the victim since the harness itself is legitimately installed and paid for.

Secure AI: Conversation history poisoning and beyond

Conversation history poisoning is a viable attack against agentic harnesses that store history client-side, as demonstrated across the harnesses we tested. Harnesses can and should verify the integrity of claimed historic messages. Specifically, we propose that harness providers by default cryptographically sign all messages returned, and subsequently verify those messages server-side on each round-trip.

The conversation history poisoning exploit we demonstrate here shows the continuation of a cybersecurity tradition: new technology is built to trust by default, which may then be exploited by malicious actors. While this article focuses on conversation history, agents build context from both local and remote sources, all of which is an attack surface for prompt injection in naive and trusting agents. Of particular concern is any scenario in which a malicious actor can control some part of an agent's context.

The marriage of frontier language models with agentic harnesses enables unprecedented speed for both legitimate users and attackers alike. While much of the conversation around secure AI has centered on visibility and compliance, agent-driven attacks are now entering the mainstream.

Darktrace / SECURE AI is our answer to this problem. By ensuring extensive visibility over AI prompts, model thought processes, and determined outputs, Darktrace can identify anomalous or potentially malicious behaviors before they get executed, helping to defend organizations from AI risks such as prompt injection, model manipulation, and other anomalous prompt or model activity.

‍

Footnotes

[1] We did not go through any responsible disclosure process with Pi. Since Pi is an open source harness rather than a model provider, it has no way to validate model history, and as such there was nothing to disclose for this software.

‍

[related-resource]

Continue reading
About the author
Eric Rozon
Senior Security Researcher
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ