Campaign or TTP Overview
In a surprising resurgence of a notorious phishing tactic, the Evil MSI Background technique has made its way back into the spotlight. This method involves embedding a payload within a JPEG image, cleverly branded to mimic MSI’s corporate identity, and distributing it via a seemingly harmless WeTransfer link. Observed in recent weeks, the campaign appears to be targeting professionals in the tech industry, attempting to exploit trust in well-known platforms such as WeTransfer and MSI.
The attackers’ ingenuity lies in their use of social engineering to craft a scenario where the recipient believes the file contains important graphics or promotional content. This method hasn’t been attributed to a specific group, but its complexity suggests a well-coordinated effort likely originating from sophisticated threat actors. For more details on this tactic, refer to SANS Internet Storm Center’s detailed analysis.
How It Was Built
The attack begins with the creation of the lure—a JPEG file ingeniously disguised as a corporate asset affiliated with MSI. This image file, however, harbors a malicious payload packaged as a seemingly innocuous background graphic. The deception unfolds when victims receive an email containing a legitimate-looking WeTransfer link, capitalizing on WeTransfer’s reputation for secure file sharing.
The typical subject line employed might read: “MSI Marketing Assets for Approval”, providing a sense of urgency and legitimacy. By masquerading as a marketing team member or graphic designer, the sender not only gains attention but also bypasses routine scrutiny. The sender email may look something like graphics@team-msi.com, using domains cleverly constructed to mimic genuine corporate assets.
From: "MSI Graphics" <graphics@team-msi.com>
Subject: MSI Marketing Assets for Approval
Link: https://wetransfer.com/downloads/secure-link
Attachment: MSI_Background.jpg
Upon downloading the JPEG file from the WeTransfer link, the unsuspecting user inadvertently executes a script embedded within the image, often leveraging vulnerabilities in outdated software to gain a foothold on the system.
Why It Worked
Three key components contribute to the success of this campaign. First, using WeTransfer for delivery significantly reduces suspicion, as recipients are conditioned to trust links to uploads hosted by this widely-used service. Second, the phishing email’s sender identity, crafted to resemble a real MSI employee or department using domains like team-msi.com, enhances legitimacy. Finally, the socially engineered framing of the email’s content, focused on urgent business communication, triggers a reflexive action from targets, compelling them to download and open the attachment without thorough verification.
Operator Takeaways
The Evil MSI Background campaign underscores the importance of authenticity and context in phishing tactics. As a red teamer, consider these elements for more convincing campaigns:
- Leverage platforms trusted by your target audience, like WeTransfer, to mask your true intentions.
- Imitate corporate identities accurately, using plausible domains and communication styles.
- Create urgency with realistic business scenarios to lower defensive skepticism while encouraging swift action.
Good / Better / Best
- Good: Use commonly recognized platforms such as Dropbox or Google Drive for lure distribution.
- Better: Craft sender identities that convincingly mimic internal contacts or trusted partners, ensuring your domain and sender name are as convincing as possible.
- Best: Integrate contextually relevant, time-sensitive communications that resonate with current business cycles or ongoing projects, enhancing the perceived need for immediate attention and action.
References
SANS Internet Storm Center’s detailed analysis
PhishingBox’s tools for phishing simulations
Related Reading
- Embedding Payloads in Image Files for Phishing Attacks
- Advanced Techniques in Payload Delivery for Phishing Campaigns
- What is a JPEG Payload in Phishing?
- Leveraging Image-Based Payload Delivery in Phishing Campaigns
Educational Purpose: This content is provided for awareness and defensive purposes only. Understanding attacker methodologies helps individuals and organizations protect themselves.

