Sarah Lam
Sarah is a Law/Computer Science student at Monash University. Additionally, she has been working as a penetration tester at Promithic for the last two years. Besides being paid to break things, she is also a Managing Editor of the Monash University Law Review and a legal research assistant.
Session
Modern email filters use a number of metrics to determine whether an incoming email is likely to be spam, including language, link/attachment analysis and sender details. For an ordinary sender, it may be an inconvenience to be sent to spam, but for a red-team operator (or threat actor), it can mean the difference between a successful or unsuccessful phishing attack. So how can the chances of a successful delivery be increased?
This talk will briefly discuss how email controls work, before exploring a novel technique for bypassing email filters: Language confusion. By using mixed-language emails, language analysis tools can be deceived, resulting in a higher rate of successful delivery. Small-scale tests in real-world environments have indicated that this is a viable strategy to improve malicious email delivery rates, so come along if you want to learn more about email controls (and maybe one or two French words).