Email Origin
Attackers manipulate the origin of an email to make it appear as though it comes from a trusted source. These techniques aim to bypass authentication checks, impersonate known entities, or exploit legitimate infrastructure to increase credibility and deliver phishing payloads.
Sub-techniques
TE0011.1
Look-Alike Domain
Attackers register domains that closely resemble legitimate ones (e.g., paypa1.com) to trick recipients into trusting the sender address.
TE0011.2
Third-Party Service Misuse
Attackers exploit trusted platforms—such as PayPal, DocuSign, Microsoft 365, or e-commerce and invoicing services—to deliver phishing content. These appear as legitimate notifications but contain links or prompts that lead to attacker-controlled infrastructure.
TE0011.3
Compromised Internal Email Account
Adversaries send phishing emails from within an organization’s own email environment by abusing compromised user accounts, making messages appear trustworthy and internally sourced.
TE0011.4
Compromised External Email Account
Legitimate but compromised accounts (e.g., vendors or partners) are used to distribute phishing emails, leveraging existing relationships to lower suspicion.
TE0011.5
Free Email Address
Attackers use public webmail services (e.g., Gmail, Outlook.com, Yahoo) to send phishing emails from accounts that appear generic, personal, or loosely affiliated with a trusted entity. These addresses often bypass basic sender validation and are used to maintain anonymity while appearing legitimate.