Executive summary
A password-spray campaign from infrastructure linked to a known commodity botnet
succeeded against one account (m.lindqvist) that lacked MFA
enforcement. Within nine minutes, the actor authenticated from a previously
unseen network, granted mailbox permissions to an unrecognized OAuth application,
and created an inbox rule that forwards and hides finance-related mail —
consistent with business-email-compromise staging. No lateral movement or data
exfiltration beyond mail-rule creation has been observed in the covered sources.
Involved entities
Timeline
- Password-spray pattern begins: 15 accounts, 1–2 attempts each, from 203.0.113.66. Individually below lockout thresholds. source: identity provider sign-in logs · detection: L2 aggregation
-
Successful authentication for
m.lindqvistfrom 203.0.113.66. Account is in a legacy group without MFA enforcement. source: identity provider sign-in logs - Second session for the same account from 198.51.100.23 — geography and ASN with no prior association to this user in its entity history. source: identity provider sign-in logs · context: entity history & scoring
- OAuth consent granted to application "Mail Sync Utility" (unverified publisher) with mail read/write scope. source: cloud audit log
- Inbox rule created: forward messages matching finance keywords to external address, mark read, move to archive. source: mailbox audit log
-
Signals associated on entity
m.lindqvistwithin scoring window — incident qualified and escalated. Qvasir association & scoring
Investigation (automated)
203.0.113.66 is flagged by two intelligence sources as commodity credential-stuffing infrastructure (first reported 11 days ago). 198.51.100.23 has no prior reputation — consistent with a clean hand-off host after initial access.
Reverse and passive DNS on 198.51.100.23 show a hosting-provider netblock with short-lived tenant churn; no organizational infrastructure resolves there.
90-day lookback: m.lindqvist has never authenticated from either
ASN; no other account has interacted with OAuth app "Mail Sync Utility"; the
14 failed spray targets show no subsequent anomalous activity.
No prior signals on this entity in the current window. The spray-success → new-network → consent-grant → inbox-rule sequence matches a staged BEC pattern rather than isolated anomalies.
MITRE ATT&CK® mapping
Recommendations
- Contain now: revoke all active sessions and reset
credentials for
m.lindqvist; revoke the OAuth grant for "Mail Sync Utility" and block the publisher. - Remove persistence: delete the inbox rule; review sent items and forwarded mail since 03:31 UTC for exposure.
- Close the gap: enforce MFA on the legacy account group — 14 additional accounts in this group were targeted in the same spray.
- Watch: a monitoring rule for new consents to unverified OAuth publishers has been drafted from this incident and is ready for review and deployment.