Cyber Security News

Threat Actors Use Email Bombing Attacks to Bypass Security Tools & Hide Activity

Email bombing attacks have emerged as a sophisticated technique in cybercriminals’ arsenals, designed to overwhelm targets’ inboxes while concealing more malicious activities beneath the flood of messages.

These attacks involve sending hundreds or thousands of emails to victims within a short timeframe, creating digital noise that makes it difficult for both users and security systems to identify truly threatening communications.

The tactic has gained popularity among threat actors because the individual emails often appear legitimate and bypass traditional security filters, as they typically originate from actual subscription services to which victims have been unknowingly registered.

The primary objective of email bombing extends beyond mere disruption.

Attackers leverage the chaos created by the influx of messages to hide social engineering attempts or malicious emails containing ransomware, credential phishing links, or other harmful payloads.

Multiple threat actors have adopted this approach, including the notorious Ransomware-as-a-Service group Black Basta (also known as Storm-1811).

What makes these attacks particularly effective is their ability to circumvent standard email security tools, which typically analyze messages individually rather than identifying patterns across message volumes.

Darktrace analysts identified a sophisticated implementation of this technique in early 2025, when their systems detected a customer being targeted with over 150 emails from 107 unique domains in under five minutes.

The behavioral analysis capabilities of Darktrace/EMAIL identified this unusual pattern despite all messages successfully bypassing the organization’s reputable Security Email Gateway (SEG). Darktrace’s analysis shows the dramatic spike in unusual emails that characterized this attack.

Graph showing the unusual spike in unusual emails (Source – Darktrace)

The attack’s impact extended well beyond email disruption. Following the email bombardment, the threat actors initiated voice phishing (vishing) attempts through Microsoft Teams, impersonating the organization’s IT department to establish trust and create a sense of urgency.

The victim, already overwhelmed by the email bombing, accepted the call. During this interaction, the attackers convinced the user to share credentials, ultimately providing access to the Microsoft Quick Assist remote management tool.

Once inside the network, the attackers’ methodology became increasingly sophisticated. The compromised device began performing LDAP reconnaissance, attempting to bind to local directory services and query user information.

Cyber AI Analyst investigation (Source – Darktrace)

This activity represents a classic post-exploitation pattern where attackers gather intelligence about the network environment before expanding their foothold.

# Example of similar LDAP reconnaissance pattern
Get-ADUser -Filter * -Properties * | Select-Object SamAccountName, UserPrincipalName, Enabled

This LDAP scanning was followed by network reconnaissance, where the attackers initiated scans of the customer’s environment and attempted connections to other internal devices.

They proceeded to make multiple SMB sessions and NTLM authentication attempts to internal systems—a common technique for lateral movement within compromised networks.

Although these connection attempts failed in this instance, they demonstrate the attackers’ methodology for expanding their control once initial access is gained through the email bombing distraction technique.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Also Read:

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago