Inbox In-Fighting: A Window Into BEC Subculture

If you work in cybersecurity incident response, threat detection, or cyber insurance, you know the standard Business Email Compromise (BEC) playbook.
A threat actor compromises an inbox and immediately sets up email routing rules to hide their tracks and intercept targeted communications. The rules these threat actors create display easily detectable, obvious characteristics.
But what happens when two independent attackers bump into each other inside the same corporate inbox? They don't just quietly ignore each other: they talk. And surprisingly, they often use the names of the inbox rules themselves as a rudimentary chat channel, meaning rules can teach us even more about them than how they redirect email.
These hidden conversations offer a fascinating, rarely seen window into the BEC subculture and provide insights into threat actors' geographies, operational tactics, attitudes, and collaborative dynamics.
How threat actors abuse email routing rules
Abusing inbox rules to evade detection (MITRE ATT&CK T1564.008) is a widespread tactic. Threat actors seek persistent access to compromised accounts to gather sensitive data, launch secondary phishing campaigns, or communicate with high-value targets. In the meantime, they do not want the compromised individual to notice any strange incoming emails or security alerts.
To the attacker’s advantage, most email platforms support automated rules by default. Threat actors can easily exploit this functionality to hide, redirect, or forward emails containing flagged keywords, such as “invoice” or “confidential.”
Inside the rule name chat room
When multiple attackers compromise a high-value target, their paths can overlap. One threat actor might delete another’s hiding rules or launch a clumsy attack that risks exposing the compromise for everyone.
Less commonly observed, individual threat actors may actually communicate within the name of an inbox rule, as Coalition Incident Response* (CIR) recently documented in an investigation:
"brr ... i've been observing this box for a while and i knew when you wrote this job, i'm sure you noticed i moved some stuffs too, i didn't want to ruin your job, [and make] a mess of the whole thing. write me on TG (telegram) @[username]. let's talk" |
|---|
The recorded threat actor is observing, calculating, and highly aware of the other intruder's presence. They act independently but appear willing to work together to ensure neither ruins the payout.
Sometimes, the interactions are far less polite. In another incident, CIR observed a prolonged, heated argument between two threat actors fighting for control over an inbox, all documented in a sequence of rule names.
Note: The following sequence contains the exact rule names created by the attackers, featuring heavy use of language consistent with Nigerian Pidgin and similar regional vernaculars:
"Bro.. I See U De Inside The Box But Na Diff Job | De Do Entirely Naw. Make We Nor Cast The Box. Let Work It Togeda. Gv Me Ur ICQ" "bro u doing like u smart …..u all fool jst know cos i can even stll call the pelle diredit spoil everthing ...so make we all comply" "u dey very stupid.. U ENTER boss see person still dey delete my filter.. God punish u there" "BRO.. GIVE ME UR ICQ... STOP! DELETING FILTERS. I'M TRYING TO COMMUNICATE WITH YOU BRO." "IF YOU DE INSIDE FOR 100 YEARS DOES THAT MATTER? I DE DO MY OWN JOB AND YOU ARE DOING YOURS. NA TODAY YOU START THIS GAME? DON'T ADDRESS PPLE YOU DON'T KNOW AGGRESSIVELY. GV ME UR ICQ." "Of course, I have studied the box and I see na CEO dem approved all wire payment from their online wire Portal. Meanwhile, ACH needs no approval from Administrator so I know what I'm doing. ICQ: @[username]" "DOESN'T MEAN WORK DON CAST. Controller, CEO and CFO direct fake invoice Instructions these days is by God's Grace. I will still respond to her." "BRO IF U RELAX AND AGREE TO WORK WITH ME WE GO CHOP THIS BOX. NA PATIENCE WE NEED.." "Bro... Make U No Use $12K Job Spoil Dis Box Naw... Owfa Wetin De ?" |
|---|

Takeaways from attacker activity
Beyond the sheer novelty of attackers fighting across inbox rule names, these chats provide important threat intelligence:
Geography and Culture
The heavy use of Nigerian Pidgin ("Make We Nor Cast" / "Owfa Wetin De") strongly ties this specific activity to well-documented West African BEC rings, although language alone does not establish the threat actors’ location or identity. "Nor cast the box" can be read as "don't expose or ruin the compromised inbox," while "chop this box" means to profit from it.
Tactics and Target Casing
The attackers aren't just blindly sending invoices; they often study the organization's specific approval workflows. One threat actor explicitly notes that wire transfers require CEO approval via an online portal, but ACH transfers do not require administrator approval. They are doing their homework once in the inbox. The time this takes can benefit the defender, and it also shows the importance of non-IT protections such as secure payment approval workflows.
Tradeoff Analysis
"Make U No Use $12K Job Spoil Dis Box Naw." The attackers are actively weighing the risk vs. reward. One actor is warning that the other is attempting a "small" $12,000 scam that might alert the victim and ruin a potentially much larger payday.
Email providers should adopt a “secure by default” posture
The fact that threat actors can comfortably create dozens of rules with full-sentence names, explicitly routing "invoice" and "wire" emails to the RSS Feeds folder, is a serious gap in default platform security.
Microsoft and other major email providers have the telemetry to see this happening at scale, yet organizations remain vulnerable to the exact same rudimentary techniques year after year. In most organizations, legitimate rule creation is rare, and legitimate use of some of these built-in folders is even rarer.
If we want to actually materially reduce BEC, providers need to adopt a "secure by default" posture. For example:
Disable inbox rules by default. Most users do not need complex, custom email routing rules. Email providers should make this an opt-in feature that requires admin approval, and keep an eye on the much-reduced attack surface.
Alert on or even block sentence-length or nonsensical rule names. No legitimate user names a rule BRO IF U RELAX AND AGREE TO WORK WITH ME WE GO CHOP THIS BOX. Or a few commas or periods (,, or ..).
Alert on payment-related criteria. A rule automatically moving emails containing "ACH", "Wire", or "Invoice" out of the primary inbox should immediately trigger a high-severity alert, in the spirit of risky Sign-ins and other Entra protections.
Disable common "hiding places" by default. Threat actors love routing emails to the RSS Feeds or Conversation History folders because users rarely check them. These should be disabled by default, and even when available, should only accept routing from known-approved sources (not via rules).
Disable external forwarding by default. Whether via SMTP or an inbox rule, auto-forwarding corporate mail to an external address should be blocked out of the box.
Threat actors are quite literally chatting with each other in our inboxes because they feel safe doing so. If teams or users really need these features, their administrators can turn them back on, in the meantime improving baseline defaults. Until the platforms we rely on start aggressively blocking these easily detectable evasion techniques by default, BEC will continue to drive cyber claims.
Start monitoring for suspicious activity
We believe that email providers play an important role in systematically reducing the popularity of BEC among cyber attackers. But we also know that a sweeping change to inbox rule features is likely not coming tomorrow. In the meantime, businesses should take appropriate measures to reduce their risk and mitigate suspicious activity before it escalates to financial loss.
To prevent the fraudulent transfer of funds, every second counts. Wirespeed Automated Detection & Response (ADR) is designed to contain threats in milliseconds and automatically take action when suspicious mailbox rules are created. Wirespeed ADR uses deterministic logic to confirm threats as malicious and reset credentials via API to block further activity — with 99% of detections resolved in under 754 milliseconds.**
Learn more about how Wirespeed stops attacks with deterministic speed.
LIGHTNING-FAST SPEED. LASER PRECISION.
Wirespeed Automated Detection & Response
Start your free 30-day trial >
