Blog
The Invisible Payload: When Your Email System Helps the Attacker

In 2025, phishing attacks took a subtle yet powerful evolutionary leap. Threat actors moved past simple spam filters, weaponizing the very systems designed to manage email delivery. At Zerosploit, our Security Operations Center (SOC) team observed a sophisticated, multi-layered operation that exposed a critical vulnerability: the implicit trust users place in automated system messages.
This campaign combined high-impact financial baits with a clever technical evasion: the abuse of Non-Delivery Reports (NDRs).

The Attack Narrative: From Bait to Bounce-Back
The campaign was designed as a two-stage relay, engineered to bypass front-line defenses and shift communication to an unmonitored channel.
Phase 1: The High-Stakes Bait
The initial message used the "Crypto Cash Back Reward" bait, claiming the recipient had won a fictitious cryptocurrency prize valued at over seven million USD.
This social engineering was a masterpiece of urgency and secrecy, instructing recipients to:
- Contact a so-called "airdrop support" team via WhatsApp.
- Provide personal information and a "payment confirmation number."
The attackers first attempted to deliver this email by spoofing internal corporate addresses from a compromised external mail server. When a recipient's security controls rejected the spoofed email, the external server automatically generated a Non-Delivery Report (NDR) or a bounce-back notification, a behavior our experts flagged as the core of the exploit.
Phase 2: The Evasion via Trust
This technical abuse is where the attack distinguished itself. [14] The automated NDRs, which are generally trusted as legitimate system warnings, contained the original, malicious "Crypto Cash Back Reward" email as an attachment (an .eml file). By exploiting this server behavior, the attackers effectively induced the enterprise system to deliver the phishing content indirectly—as part of an "error investigation." This successfully circumvented typical content-based email filtering and reduced immediate suspicion from users. [15]
This same evasive technique was also used in the "Delivery Check Failed" theme, which leveraged user anxiety to harvest credentials via fake verification pages.
Expert Observations and Defensive Implications
Through continuous monitoring, the Zerosploit team confirmed over 200 observed instances of this campaign across the organization, demonstrating persistent attacker interest and a sustained tradecraft tailored to enterprise defenses. [16]
The observed payloads led to:
- Credential Harvesting from fake sign-in portals (T1110).
- Spearphishing via Service through WhatsApp redirection (T1566.003).
- Irreversible Financial Loss through advance fees or wallet draining (T1486).
This coordinated, multi-layered tactic demonstrates a mature exploitation of email infrastructure, extending the attack surface to automated system messages. Effective defense requires more than filtering — it demands user awareness to detect threats hidden within seemingly harmless system errors.