
Summary
Detects inbound messages that minimize visible body text to almost nothing and include a single link, where an inline image acts as both the message body and the link destination. The rule requires exactly one inline image attachment, performs OCR on the image, and runs the extracted text through an NLU classifier to identify credential-theft intents (e.g., fake voicemail transcripts, document-sharing notifications, workflow addendum requests). It confirms a credential-phishing scenario by checking for a cred_theft intent, ensuring the link in the thread points to a domain outside the sender’s domain, and excluding high-trust senders that pass DMARC to reduce false positives. Detection methods include OCR, NLU, HTML analysis, header/sender analysis, and sender/link-domain correlation. The rule is categorized under Credential Phishing with tactics and techniques focused on image-based content, social engineering, and evasion of typical text-based detection.”
Categories
- Network
- Web
Data Sources
- Image
- File
- Web Credential
Created: 2026-09-26