Protecting organizations from AI-assisted executive impersonation and invoice fraud
AI-assisted BEC campaign impersonates executives to trick finance teams into fraudulent ACH payments.
Summary
Microsoft has identified an AI-assisted business email compromise (BEC) campaign that impersonates executives to defraud finance teams. The campaign, which sent over a million emails, used generative AI to craft convincing lures, including fabricated invoices and email threads, to trick recipients into initiating ACH payments of approximately $50,000. The threat actor impersonated CEOs and leveraged third-party email infrastructure, while impersonating legitimate organizations like ServiceNow without their compromise.
Full text
Share Link copied to clipboard! TagsSocial engineeringContent typesResearchProducts and servicesMicrosoft DefenderTopicsActionable threat insightsAI and agentsThreat intelligence Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further. In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation. The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated). Attack chain overview The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers. Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft. Email Delivery Between August 3 and 5, Microsoft detected a campaign consisting of more than a million emails targeting enterprise users. The attacker used multiple third-party email service accounts to send out the emails. A huge majority of these emails were sent to users in the United States (87.7% of the total campaign). Figure 2. Campaign timeline. Figure 3. Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others. Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism. The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature. Email bodies contained a simple and direct “approval” of the “invoice below” as well as urged users to request a PDF version if they need it. Additionally, as mentioned earlier, the email signature contained certain details about the spoofed CEO such as name and email address. Figure 4. Spoofed message from executive team member. Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains. Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity. Rather, the campaign relied on fraudulent domains and content designed to mimic trusted brands and individuals. The threat actor did not stop there. To add further legitimacy, directly below the CEO signature, the actor included “forwarded” content , specifically a professional looking but fabricated “ServiceNow Platform — Annual Subscription” invoice. The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method, and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor. Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name. The invoice shown below is a threat actor-created impersonation and was not issued by ServiceNow. Figure 5. Spoofed ServiceNow invoice. Finally, directly below the fake invoice, two more “forwarded” emails are included which are essentially a short conversation between the two spoofed executives (the targeted company executive, and ServiceNow President). The two executives are seen discussing the ServiceNow purchase, implementation and handling of the invoice. Figure 6. “Forwarded” replies thread within the email lacking usual headers. From a defender point of view there are several indicators within the email indicating that the email and the “forwarded” thread are not genuine. “From” headers from the spoofed thread lack any data headers like actual forwarded emails. Suspicious language used in the spoofed thread such as “no need to copy me”. Suspicious language in headers i.e display name not matching sender address, subjects using financial lure keywords like ‘due bill’, ‘ACH Parment’ etc. Despite the sophistication of the generated content, several inconsistencies remained visible to defenders In real email threads, the previous threads are normally tabbed or otherwise visually grouped, while the previous threads in this example were left aligned. An additional inconsistency was observed where the targeted company’s CEO requested the recipient to send the invoice directly to victims and not CC the sender. However, in the most recent thread, the CEO stated that the invoice is approved and the invoice is sent from his address. Domain registration Before initiating the campaign, the threat actor registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign activity was observed. This domain was used for the spoofed email address of ServiceNow President. It was also used in several places in the fabricated invoice such as in the contact email in case of any questions. The actor also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email. Figure 7. Account information linked with email of impersonated domain. Generative AI usage Microsoft observed several indicators consistent with AI-assisted template development. These included extensive HTML comments, structured section labeling, and highly uniform template construction. While these indicators suggest generative AI involvement, they do not independently establish the extent to which AI generated campaign content. Examples: Figure 8. Code snippet showing a verbose HTML comment describing a section (a characteristic commonly observed in AI-generated code). Figure 9. Another code snippet showing extensive comments on HTML style elements and sections. Additionally, the use of ‘em dash’ (“—”) and banner ‘===========’ have also become other indicators associated with AI usage. Figure 10. Another code example indicating AI usage. This example shows a verbose capitalized section header and yet more style elements excessively commented. One possible indication of template-based generation is that invoice identifiers and narrative structure remained largely consistent across samples while organization-specific details changed between targets. Mitigation and protection guidance Microsoft provides layered protection against this ty
Indicators of Compromise
- malware — ACH payment fraud