Blog

The Invisible Payload: When Your Email System Helps the Attacker

By Mohammed Mahalawy
The Invisible Payload: When Your Email System Helps the Attacker

In 2025, phishing attacks took a subtle yet powerful evolutionary leap. Threat actors moved past simple spam filters, weaponizing the very systems designed to manage email delivery. At Zerosploit, our Security Operations Center (SOC) team observed a sophisticated, multi-layered operation that exposed a critical vulnerability: the implicit trust users place in automated system messages.

This campaign combined high-impact financial baits with a clever technical evasion: the abuse of Non-Delivery Reports (NDRs).

Infographic — the NDR phishing campaign in four phases. Phase 1, the high-stakes bait: attackers spoof internal addresses with urgent themes like “Crypto Cash Back Rewards” or “Delivery Check Failed.” Phase 2, technical evasion via NDRs: when the spoof is rejected, the system automatically sends a “Non-Delivery Report” to the user containing the malicious email as an attachment. Phase 3, exploiting user trust: users trust these automated system notifications, inadvertently opening the attached .eml file and bypassing content filters. The final pivot: payloads redirect victims to WhatsApp for social engineering or fake portals to harvest login credentials. High-frequency enterprise threat: Zerosploit SOC observed over 200 instances of this campaign leading to credential theft and financial loss.

The Attack Narrative: From Bait to Bounce-Back

The campaign was designed as a two-stage relay, engineered to bypass front-line defenses and shift communication to an unmonitored channel.

Phase 1: The High-Stakes Bait

The initial message used the "Crypto Cash Back Reward" bait, claiming the recipient had won a fictitious cryptocurrency prize valued at over seven million USD.

This social engineering was a masterpiece of urgency and secrecy, instructing recipients to:

  • Contact a so-called "airdrop support" team via WhatsApp.
  • Provide personal information and a "payment confirmation number."

The attackers first attempted to deliver this email by spoofing internal corporate addresses from a compromised external mail server. When a recipient's security controls rejected the spoofed email, the external server automatically generated a Non-Delivery Report (NDR) or a bounce-back notification, a behavior our experts flagged as the core of the exploit.

Phase 2: The Evasion via Trust

This technical abuse is where the attack distinguished itself. [14] The automated NDRs, which are generally trusted as legitimate system warnings, contained the original, malicious "Crypto Cash Back Reward" email as an attachment (an .eml file). By exploiting this server behavior, the attackers effectively induced the enterprise system to deliver the phishing content indirectly—as part of an "error investigation." This successfully circumvented typical content-based email filtering and reduced immediate suspicion from users. [15]

This same evasive technique was also used in the "Delivery Check Failed" theme, which leveraged user anxiety to harvest credentials via fake verification pages.

Expert Observations and Defensive Implications

Through continuous monitoring, the Zerosploit team confirmed over 200 observed instances of this campaign across the organization, demonstrating persistent attacker interest and a sustained tradecraft tailored to enterprise defenses. [16]

The observed payloads led to:

  • Credential Harvesting from fake sign-in portals (T1110).
  • Spearphishing via Service through WhatsApp redirection (T1566.003).
  • Irreversible Financial Loss through advance fees or wallet draining (T1486).

This coordinated, multi-layered tactic demonstrates a mature exploitation of email infrastructure, extending the attack surface to automated system messages. Effective defense requires more than filtering — it demands user awareness to detect threats hidden within seemingly harmless system errors.