Lune

USENIX Security2025

Doubly Dangerous: Evading Phishing Reporting Systems by Leveraging Email Tracking Techniques

Anish Chand, Nick Nikiforakis, Phani Vadrevu

2025年份

摘要

Given the significant threat posed by email as a highly prevalent phishing attack vector, we undertake the first study focused on real-world phishing email reporting systems. Our key idea in performing this study is to repurpose email tracking, a well-known privacy threat vector, for profiling and evading anti-phishing systems employed by popular email services. Our results show that the reporting systems of all major email services we tested are vulnerable to evasive phishing attacks affecting more than 2 billion users worldwide. We propose several countermeasures that email service operators can adopt to help ameliorate this issue in the future. We disclosed our findings to the affected email providers which resulted in remedial changes and a vulnerability reward. Objective. With this paper, we aim to answer two main questions: (Q1) How do email services handle the phishing reports that they receive from users? (Q2) Can attackers abuse email-based phishing reports to fingerprint phishing detectors and cloak their malicious infrastructure from them, achieving long-lasting phishing campaigns? Key idea: weaponizing email tracking. Our key idea is based on a threat vector that is traditionally associated with web privacy, that of email tracking [29] . Email tracking enables senders to monitor if and when an email has been opened, and in some cases, where it was accessed from. This is achieved by leveraging the fact that most email clients support HTML-based emails with embedded remote objects, such as images. The loading of these images serves as a side channel to deduce the act of email opening.