Malicious Email Address
Attackers use deceptive email addresses as payloads, embedding them in phishing emails to trick victims into contacting attackers directly. These addresses may appear in the sender field, email body, or reply-to field, leading victims to engage in fraudulent communication.
Sub-techniques
TE0023.1
Reply-To Contains Look-alike Domain
The Reply-To address closely resembles a trusted domain (e.g., paypal-support.com instead of paypal.com), deceiving recipients into responding to attackers.
TE0023.2
Reply-To Contains Free Email Address
The Reply-To field is set to a free email service (e.g., [email protected]) to direct victim communication to an attacker-controlled email.
TE0023.3
Email Body Contains Look-alike Domain
The email body includes a deceptive email address with a look-alike domain, encouraging recipients to respond directly to the attacker.
TE0023.4
Email Body Contains Free Email Address
The attacker embeds a free email address in the message as a contact point, directing victims to communicate outside secure channels.