Mailbox rules can become persistence
A rule that quietly forwards or deletes mail is one of the most effective and least noticed footholds an attacker can leave.
It survives a password change, needs no malware and hides the evidence: replies to the fraudulent request get moved out of the inbox before the victim sees them. Reviewing mailbox rules is a standard part of investigating a compromised account and is rarely part of routine monitoring.
More on Email security
- DKIM protects signed content against later modificationChange one word, break the seal
- DMARC depends on alignmentBoth names, or neither
- Forwarding can break email authentication assumptionsIt was re-posted on the way
- A display name is not an email addressThey wrote that name themselves
- Reply-chain hijacking borrows existing trustTrust borrowed from the thread
- Secure email gateways see only traffic that reaches themIt only sees what comes past it
