Corporate organizations, financial brokerages, and textile exporters across Pakistan face an escalating wave of highly targeted Business Email Compromise (BEC) and executive impersonation attacks. In these sophisticated “CEO fraud” schemes, cybercriminals register visually identical lookalike domains (e.g. c0rp.com.pk instead of corp.com.pk) or spoof executive display names, issuing urgent instructions to accounting teams to divert millions of rupees in supplier invoice payments to fraudulent bank accounts.
Standard Bayesian spam filters (like default SpamAssassin) frequently fail to catch these attacks because the emails contain no obvious malware attachments or traditional spam keywords—they read like ordinary business correspondence.
Hosting corporate email infrastructure on bare-metal Dedicated Servers gives administrators root-level power to deploy custom Exim System Transport Filters. By evaluating raw email headers, display name mismatches, and banking trigger phrases before messages ever reach the user’s inbox, you can intercept and neutralize financial fraud in real time.
Understanding the Exim System Filter Pipeline
Unlike per-user mail filters configured inside cPanel’s webmail interface, an Exim System Filter executes globally with root privileges before local delivery routing occurs:
- Envelope Arrival: An external mail server connects to Exim and delivers an email payload.
- System Filter Inspection: Exim passes the raw message headers and body through the centralized system filter script (
/etc/cpanel_exim_system_filter). - Regex Pattern Evaluation: The filter checks:
- Does the
From:display name contain an internal executive’s name (e.g. “Mian Muhammad - CEO”) while theReply-To:or envelope sender belongs to an external Gmail/Proton address? - Does the email body contain wire transfer keywords paired with urgent banking routing codes?
- Does the
- Execution Action: If matched, the filter can silently drop the message, append warning headers (
X-Security-Warning: External Executive Impersonation), or divert it into a quarantined security compliance mailbox.
Inbound Email Arrives
│
▼
[Exim MTA Ingress]
│
▼
[Global System Filter (/etc/cpanel_exim_system_filter)]
│
┌────────┴────────────────────────────────────────┐
▼ ▼
Clean Message Matches Phishing Pattern
Deliver to Inbox (Display Name Spoof / Fake IBAN)
├── Append High-Visibility Warning Banner
└── Divert Copy to Security Ops (/quarantine/)
Step 1: Enabling and Customizing the Exim System Filter
In cPanel, global filtering is governed by /etc/cpanel_exim_system_filter. Never edit this file directly, as cPanel updates will overwrite your changes. Instead, create a custom template copy:
# Create persistent system filter drop-in
cp /etc/cpanel_exim_system_filter /etc/cpanel_exim_system_filter_custom
chmod 644 /etc/cpanel_exim_system_filter_custom
chown root:mail /etc/cpanel_exim_system_filter_custom
Instruct WHM to use this custom filter file:
- Navigate to WHM > Service Configuration > Exim Configuration Manager > Basic Editor > Filters.
- Set Exim System Filter File to
/etc/cpanel_exim_system_filter_custom. - Save changes.
Step 2: Crafting BEC & Financial Spoofing Filter Rules
Append the following defensive rules to the bottom of /etc/cpanel_exim_system_filter_custom:
# /etc/cpanel_exim_system_filter_custom - NextGen Anti-Phishing Rules
# 1. Executive Display Name Spoofing Defense
# Flags external emails attempting to pose as the CEO or CFO
if
$h_from: contains "Tariq Malik" or
$h_from: contains "Chief Executive Officer"
then
if $sender_address does not contain "@nextgen.pk" then
headers add "X-NextGen-Security: SUSPECTED_EXECUTIVE_IMPERSONATION"
headers add "Subject: [EXTERNAL SPOOF WARNING] $h_subject:"
deliver "[email protected]"
endif
endif
# 2. Wire Transfer & Fake Invoice Phishing Intercept
# Blocks dangerous execution scripts bundled in ZIP/ISO/IMG containers
if $header_content-type: matches "(?i)multipart/mixed" then
if $message_body: matches "(?i)(urgent payment|wire transfer|updated bank account|change in iban|swift code)" then
if $message_body: matches "(?i)\\.(iso|img|vbs|exe|scr|bat|ps1)\\b" then
fail text "Message rejected by enterprise policy: Suspected malicious financial attachment."
seen finish
endif
endif
endif
# 3. Warning Injection for First-Time External Senders
if $sender_address does not contain "@nextgen.pk" then
if $h_subject: matches "(?i)(invoice|overdue payment|remittance)" then
headers add "X-Security-Notice: EXTERNAL SENDER - Verify banking details verbally before processing funds."
endif
endif
Step 3: Rebuilding Exim Configuration and Applying Rules
Rebuild Exim’s runtime maps and restart the mail service to compile the system filter:
/scripts/buildeximconf
/scripts/restartsrv_exim
Verify that Exim accepts the custom filter syntax without syntax errors:
# Test system filter syntax
exim -bV
Step 4: Auditing Filter Hits in Real Time
Inspect /var/log/exim_mainlog for custom filter intercepts:
# Monitor system filter triggers
grep -E "(SUSPECTED_EXECUTIVE_IMPERSONATION|soc-quarantine)" /var/log/exim_mainlog
Look for explicit log entries confirming intercept:
2026-09-30 17:05:12 1sX8fB-0002bA-3c <= [email protected] H=(mail-lj1-f175.google.com) [209.85.218.175] P=esmtps S=2415 [email protected]
2026-09-30 17:05:12 1sX8fB-0002bA-3c => [email protected] <[email protected]> R=central_filter T=local_delivery
Deploying custom Exim transport filters on bare-metal Dedicated Servers in Pakistan empowers security administrators to prevent multi-million rupee financial wire scams, defend brand reputation, and ensure comprehensive email protection across all corporate domains.
Defend Your Corporate Communications with NextGen Dedicated Servers
Protect your business from CEO fraud, spear-phishing, and ransomware attacks with custom Exim transport filters, dedicated IP routing, and enterprise hardware security in Pakistan.
Explore Pakistan Dedicated Servers