Microsoft warns of phishing campaigns targeting Outlook Web App and Office 365 users
According to preliminary statistics from the end of December 2020 to now, more than 400,000 login information of OWA and Office 365 users worldwide has been stolen. In addition, there are signs that this malicious campaign is continuing to scale and sophistication to abuse new legitimate services, with the ultimate goal of bypassing secure email gateways ( Secure Email Gateways - SEGs).
The recently documented attacks are in fact part of a series of phishing campaigns collectively known as the "Compact" Campaign, which has been going on since early 2020.
" Scammers continue to succeed in using compromised accounts on email marketing services, then using these accounts to send malicious emails from legitimate IP domains and ranges", Microsoft security experts said. "They take advantage of legitimate configuration settings to ensure they can send malicious emails, bypass phishing email detection solutions ."
Outdid the SEGs
The attackers behind this phishing campaign stole more than 400,000 Office 365 and Outlook Web Access credentials since last December. Their phishing emails are disguised as announcements from video conferencing services, various security solutions, as well as business support solutions for added legitimacy.
In addition, hackers also used the compromised accounts for the SendGrid and MailGun emailing services, taking advantage of secure email portals to legalize malicious activity, making them listed as worthy domains. trust. This allows a large amount of phishing emails to bypass the SEG security barrier and reach the target's inbox.
When victims click on links embedded in malicious emails, they are immediately redirected to phishing landing pages, designed to impersonate Microsoft login pages.
" In December 2020, the malicious landing page in this campaign impersonated an Outlook Web App service to trick the target into entering their credentials. In January 2021, the fake landing page resumed its replacement. change, impersonate the Office 365 login website to steal the login information of users of this service ', the report from WMC Global pointed out.
As observed by security experts, this fraud is showing signs of increasing, as scammers are also abusing both Amazon's Simple Email Service (SES) and cloud computing platform Appspot ( used to develop and host web applications in Google-managed data centers) to send phishing emails and generate multiple impersonating URLs targeting each target.
You should read it
- [Infographic] 4 types of Phishing are easy to trap users
- Outlook on Android is about to add phishing email feature
- Warning: New email phishing tactics appear
- How to identify phishing emails
- Beware of the 7 most common types of spam
- Phishing attack: The most common techniques used to attack your PC
- GitHub is under strong phishing attack, users pay attention to account security
- The only secure email is the text-only email
May be interested
- The Purple Fox malware targets vulnerable Windows systems worldwidepurple fox, a strain of malware that was once spread around the world through sophisticated phishing email and exploit kits, has just shown signs of reappearing in a dangerous and unpredictable way. than.
- The steganography technique can hide malicious files in images on Twittera cybersecurity expert has made a stir in security circles by revealing a relatively detailed method of hiding up to 3mb of data inside an image on the social networking platform twitter.
- Hackers hide stolen credit card data in JPG filewe all know that the cybercrime world is constantly moving, parallel and has a close relationship with the development of the internet in general. that is why new hacking techniques, more sophisticated phishing techniques, are constantly being introduced by cybercriminals.
- The Linux vulnerability series is more than '15 years old', allowing hackers to hijack root privilegesvulnerabilities are currently being tracked with identifiers cve-2021-27365, cve-2021-27363, and cve-2021-27364.
- Detecting two unusual versions of ransomware, shows that the world of ransomware has become diversifiedinternational cybersecurity researchers recently found two completely new types of ransomware that are quite strange. they carry very different and rarely recorded features, which are the alarm bells, showing that the world of ransomware has become diverse.
- The Microsoft MSERT tool can find web shells related to the Exchange Server attack campaignmicrosoft has just released a new update to msert, which comes with the ability to detect web shells deployed in recent exchange server attacks.