Suspicious Inbox Rule Hiding Mail to Deleted Items via M365 Exchange

PremiumReviewedSigma · Medium · v1
Product
m365
Service
exchange
Author
HuntRule
Published
2026-09-27
Updated
2026-09-27

ATT&CK techniques

Defense Evasion → Collection
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects inbox rules that match on the @ character and move matching messages to the Deleted Items folder in Microsoft 365. This behavior was used in the Huntress traitorware intrusion to hide reply and alert traffic, a common business email compromise evasion technique that conceals ongoing mailbox abuse from the legitimate user.

Related detections9 linkedT1564.008 — drag to rearrange
Suspicious SCATTERED SPIDER Exchange Transport Rule Creation to Suppress Alerts (via m365)
Malicious Exchange Mailbox Export to ASPX via New-MailboxExportRequest
Suspicious Email-Hiding Inbox Rule Creation (via exchange)
Suspicious Inbox Rule Moving Mail to Junk for Concealment (via m365)
Suspicious Exchange Online Mail Flow Rule or Connector Creation via Compromised Account
Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Microsoft 365 Audit Logs: Inbox Rule Creation or Update with Email Hiding Actions
O365 Mail Forwarding and Redirecting Rule Changes
Suspicious Inbox Rule Hiding Mail to Deleted Items via M365 Exchange
Pivot detection · T1564.008 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.