Baiting attacks are on the rise and it seems that hackers distributing this specific type of phishing emails prefer to use Gmail accounts to carry out their attacks.
According to a report by Barracuda, which surveyed 10,500 organizations, 35% of them received at least one bait attack email in September 2021 alone.

See also: Phishing campaign used Proofpoint to scam users
What is a baiting attack?
A “bait attack” is a subcategory of phishing where threat actors attempt to gather key information about a specific target and use it for more targeted and effective attacks in the future.
It is a preparatory identification step that is rarely accompanied by payloads or embedded links in the email body.

While some of these emails contain a basic question or something that has a higher chance of getting a response, many don't include any text at all.
See also: Phishing emails infect victims with MirCop ransomware
While it may seem strange to send a nearly blank email, threat actors use it for the following purposes:
- Confirm that the recipient's email address is valid
- Confirm that the email address is actively used
- Confirm the sensitivity of targets to spam emails
- Test the effectiveness of automated spam detection solutions
Since these emails do not include links to phishing sites and do not carry attachments, they usually pass through phishing defense systems as they are not considered malicious.
Why Gmail?
Barracuda statistics show that 91% of all these bait emails are sent from new Gmail accounts, while all other email platforms account for just 9%.
This preference is due to Gmail being a very popular service that people associate with legitimacy and reliability.
The same applies to email security solutions that treat Google's email service as a highly reliable service.
See also: Mobile phishing attacks: 161% increase against the energy sector
Additionally, Gmail is a platform that allows for quick and easy creation of alias accounts without much fuss.
Finally, Gmail supports the “read receipt” feature, which tells hackers that the recipient opened the message even if they never replied.
This fulfills the purpose of the baiting attack, which is to confirm that the mailbox is valid and actively used.
Barracuda decided to experiment by responding to these baiting emails, which are not supposed to initiate the phishing process.
Within 48 hours, the security company employee received a targeted phishing attack that was used after a false Norton LifeLock purchase claim.

This rapid response demonstrates the preparedness of threat actors and the close connection between these harmless-looking blank emails and full-blown phishing attacks.
Information source: bleepingcomputer.com
