Microsoft warns of phishing campaigns targeting Outlook Web App and Office 365 users
According to preliminary statistics from the end of December 2020 to now, more than 400,000 login information of OWA and Office 365 users worldwide has been stolen. In addition, there are signs that this malicious campaign is continuing to scale and sophistication to abuse new legitimate services, with the ultimate goal of bypassing secure email gateways ( Secure Email Gateways - SEGs).
The recently documented attacks are in fact part of a series of phishing campaigns collectively known as the "Compact" Campaign, which has been going on since early 2020.
" Scammers continue to succeed in using compromised accounts on email marketing services, then using these accounts to send malicious emails from legitimate IP domains and ranges", Microsoft security experts said. "They take advantage of legitimate configuration settings to ensure they can send malicious emails, bypass phishing email detection solutions ."
Outdid the SEGs
The attackers behind this phishing campaign stole more than 400,000 Office 365 and Outlook Web Access credentials since last December. Their phishing emails are disguised as announcements from video conferencing services, various security solutions, as well as business support solutions for added legitimacy.
In addition, hackers also used the compromised accounts for the SendGrid and MailGun emailing services, taking advantage of secure email portals to legalize malicious activity, making them listed as worthy domains. trust. This allows a large amount of phishing emails to bypass the SEG security barrier and reach the target's inbox.
When victims click on links embedded in malicious emails, they are immediately redirected to phishing landing pages, designed to impersonate Microsoft login pages.
" In December 2020, the malicious landing page in this campaign impersonated an Outlook Web App service to trick the target into entering their credentials. In January 2021, the fake landing page resumed its replacement. change, impersonate the Office 365 login website to steal the login information of users of this service ', the report from WMC Global pointed out.
As observed by security experts, this fraud is showing signs of increasing, as scammers are also abusing both Amazon's Simple Email Service (SES) and cloud computing platform Appspot ( used to develop and host web applications in Google-managed data centers) to send phishing emails and generate multiple impersonating URLs targeting each target.
You should read it
- [Infographic] 4 types of Phishing are easy to trap users
- Outlook on Android is about to add phishing email feature
- Warning: New email phishing tactics appear
- How to identify phishing emails
- Beware of the 7 most common types of spam
- Phishing attack: The most common techniques used to attack your PC
- GitHub is under strong phishing attack, users pay attention to account security
- The only secure email is the text-only email
May be interested
- Google's free services are exploited by hackers for phishing campaignshackers are taking advantage of free users' services and tools to create phishing campaigns. based on the reputation and popularity of google, hackers easily steal login information or trick users into installing malware.
- Meta warns of new malware threats, including ChatGPT spoofing malwaremeta has just announced the company's latest efforts to identify and prevent malware campaigns targeting business users.
- Outlook on Android is about to add phishing email featurethe most commonly used method of cybercriminals is to send a fraudulent email to the victim's gullibility.
- 4 things to expect in Microsoft Office 15microsoft should improve the office version on the web, allowing automatic synchronization of data to the 'cloud', to the office version for android or ios.
- Microsoft is about to roll out the new Outlook client to more users, what's remarkable?it's been almost 10 months since microsoft first announced a new version of the one outlook app with a host of feature and interface improvements.
- How to add email signatures in Microsoft Office 365quantum has instructed how to add email signatures in outlook 2010, 2016. but what if you use microsoft outlook web app in office 365? today's article will show you how to insert and change signatures in outlook web app in office 365.
- Fix Outlook and Office 365 errors with just one clickif you experience any issues or problems in outlook and office 365, you can use the microsoft support and recovery assistant tool for office 365 to fix and resolve issues quickly.
- Some tips for Outlook 2013outlook 2013 is no stranger to many users. but how to use outlook 2013 effectively, not everyone knows. with the outlook 2013 tips below, make sure you will master this application more easily.
- New phishing tool targets Microsoft 365 and Gmail accountsa new phishing toolkit called tycoon 2fa that is capable of tricking and taking over even well-protected accounts is targeting microsoft 365 and gmail accounts.
- Microsoft shows how to avoid trapping phishingmicrosoft has issued a warning and recommended ways to protect users of e-mail services ...