← Back to Explore
sublimemediumRule
Service abuse: Arketa notification callback scam
Detects messages sent from Arketa's notification address (no-reply@notifications.arketa.co) that has been abused to deliver callback scam content. The rule flags messages where an NLU classifier identifies callback scam intent, or where the body references well-known brands (e.g., McAfee, Norton, PayPal, eBay, Best Buy) alongside scam-related keywords (purchase, invoice, refund, cancel, etc.) and includes a phone number formatted to evade detection through character substitution or spacing tricks.
Detection Query
type.inbound
and sender.email.email == "no-reply@notifications.arketa.co"
and (
any(ml.nlu_classifier(body.current_thread.text).intents,
.name == "callback_scam" and .confidence != "low"
)
or (
regex.icontains(body.current_thread.text,
(
"mcafee|n[o0]rt[o0]n|geek.{0,5}squad|paypal|ebay|symantec|best buy|lifel[o0]ck"
)
)
and (
3 of (
strings.ilike(body.current_thread.text, '*purchase*'),
strings.ilike(body.current_thread.text, '*payment*'),
strings.ilike(body.current_thread.text, '*transaction*'),
strings.ilike(body.current_thread.text, '*subscription*'),
strings.ilike(body.current_thread.text, '*antivirus*'),
strings.ilike(body.current_thread.text, '*order*'),
strings.ilike(body.current_thread.text, '*support*'),
strings.ilike(body.current_thread.text, '*receipt*'),
strings.ilike(body.current_thread.text, '*invoice*'),
strings.ilike(body.current_thread.text, '*call*'),
strings.ilike(body.current_thread.text, '*cancel*'),
strings.ilike(body.current_thread.text, '*renew*'),
strings.ilike(body.current_thread.text, '*refund*'),
strings.ilike(body.current_thread.text, '*host key*')
)
)
// phone number regex
and any([body.current_thread.text, subject.subject],
regex.icontains(strings.replace_confusables(.),
'\+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4}',
'\+?([ilo0-9]{1,2})?\s?\(?\d{3}\)?[\s\.\-⋅]{0,5}[ilo0-9]{3}[\s\.\-⋅]{0,5}[ilo0-9]{4}',
'[\+\x{FF0B}]?(?:\p{N}[^\p{N}]{0,3}){10,11}'
)
)
)
)
Data Sources
Email MessagesEmail HeadersEmail Attachments
Platforms
email
Raw Content
name: "Service abuse: Arketa notification callback scam"
description: "Detects messages sent from Arketa's notification address (no-reply@notifications.arketa.co) that has been abused to deliver callback scam content. The rule flags messages where an NLU classifier identifies callback scam intent, or where the body references well-known brands (e.g., McAfee, Norton, PayPal, eBay, Best Buy) alongside scam-related keywords (purchase, invoice, refund, cancel, etc.) and includes a phone number formatted to evade detection through character substitution or spacing tricks."
type: "rule"
severity: "medium"
source: |
type.inbound
and sender.email.email == "no-reply@notifications.arketa.co"
and (
any(ml.nlu_classifier(body.current_thread.text).intents,
.name == "callback_scam" and .confidence != "low"
)
or (
regex.icontains(body.current_thread.text,
(
"mcafee|n[o0]rt[o0]n|geek.{0,5}squad|paypal|ebay|symantec|best buy|lifel[o0]ck"
)
)
and (
3 of (
strings.ilike(body.current_thread.text, '*purchase*'),
strings.ilike(body.current_thread.text, '*payment*'),
strings.ilike(body.current_thread.text, '*transaction*'),
strings.ilike(body.current_thread.text, '*subscription*'),
strings.ilike(body.current_thread.text, '*antivirus*'),
strings.ilike(body.current_thread.text, '*order*'),
strings.ilike(body.current_thread.text, '*support*'),
strings.ilike(body.current_thread.text, '*receipt*'),
strings.ilike(body.current_thread.text, '*invoice*'),
strings.ilike(body.current_thread.text, '*call*'),
strings.ilike(body.current_thread.text, '*cancel*'),
strings.ilike(body.current_thread.text, '*renew*'),
strings.ilike(body.current_thread.text, '*refund*'),
strings.ilike(body.current_thread.text, '*host key*')
)
)
// phone number regex
and any([body.current_thread.text, subject.subject],
regex.icontains(strings.replace_confusables(.),
'\+?([ilo0-9]{1}.)?\(?[ilo0-9]{3}?\)?.[ilo0-9]{3}.?[ilo0-9]{4}',
'\+?([ilo0-9]{1,2})?\s?\(?\d{3}\)?[\s\.\-⋅]{0,5}[ilo0-9]{3}[\s\.\-⋅]{0,5}[ilo0-9]{4}',
'[\+\x{FF0B}]?(?:\p{N}[^\p{N}]{0,3}){10,11}'
)
)
)
)
attack_types:
- "Callback Phishing"
tactics_and_techniques:
- "Social engineering"
- "Impersonation: Brand"
- "Evasion"
- "Out of band pivot"
detection_methods:
- "Natural Language Understanding"
- "Content analysis"
- "Sender analysis"
id: "d254019b-9120-571d-9baa-e4d13407fa23"