Behind the cloak: Correlating evasive phishing campaigns in enterprise email ecosystems

Boulila, Elyssa
Thesis

FR">Despite significant academic research, advances in detection technologies, and widespread user awareness initiatives, phishing continues to be one of the most prevalent threats in the digital landscape. This observation highlights that considerable work remains in order to effectively address this issue. In this context, this thesis aims to contribute to a deeper understanding of this evolving ecosystem and provides actionable insights to support more resilient prevention and mitigation strategies. In particular, it investigates a critical and underexplored subset of phishing attacks: evasive campaigns that successfully bypassed advanced enterprise email security defenses. These stealthy attacks expose a significant blind spot in current security mechanisms, as their success directly translates into tangible operational risks, including account compromise, financial loss, and organizational damage.

FR">We first present a taxonomy of phishing evasion techniques, highlighting the challenges posed by these techniques to existing detection mechanisms. We then emphasize the critical role of cloaking in protecting malicious pages from automated analysis and derive key design recommendations for phishing crawlers.

FR">Building on these insights, we introduce CrawlerBox an open-source automated email analysis infrastructure designed to counter fingerprinting-based cloaking. Leveraging real-world datasets of user-reported emails from multiple organizations, we show that stealthy phishing campaigns are often low-volume, highly targeted, and strategically prepared in advance, including early domain registration and the use of sophisticated evasion mechanisms such as the abuse of browser fingerprinting libraries. This work also led to several practical contributions. For example, we release CrawlerBox as an open-source analysis infrastructure to support the reproducibility of our research. In particular, CrawlerBox features a crawler capable of bypassing advanced protections, an achievement recognized through a bug bounty award. In addition, we discovered a vulnerability in QR-code email parsers that was actively exploited by attackers. Finally, we responsibly disclosed our findings to the affected security vendors, providing recommendations to strengthen their products. To address emerging threats, we further propose QUASAR, a modular prototype system for mitigating QR-code-based phishing through deep inspection and secure reconstruction of encoded content.  

FR">Subsequently, we introduce an analyst-oriented phishing correlation methodology based on Multi-Criteria Decision Analysis (MCDA). Drawing on the analysis of a rich set of user-reported spear-phishing emails, our findings show that these messages are not isolated events. Rather, they are part of broader campaigns that unfold over extended periods and are characterized by subtle yet persistent behavioral patterns. These results provide evidence that phishing activity evolves gradually, driven by continuous adaptations in message content, as well as in evasion and anti-analysis techniques. By enabling the longitudinal analysis of stealthy phishing activity, our methodology supports analysts in identifying related events over time and in generating actionable hypotheses regarding emerging threats, shared tooling, and persistent attack strategies. Finally, we provide future research directions to build upon the contributions of this thesis. 


Type:
Thesis
Date:
2026-09-24
Department:
Digital Security
Eurecom Ref:
8870
Copyright:
© EURECOM. Personal use of this material is permitted. The definitive version of this paper was published in Thesis and is available at :
See also:

PERMALINK : https://www.eurecom.fr/publication/8870