New Sophisticated Phishing Attack Exploiting Microsoft 365 Infrastructure To Attack Users
ID: c2ae080a-22c4-54fb-9201-3d48a1c1de85
STIX ID: report--c2ae080a-22c4-54fb-9201-3d48a1c1de85
Feed Name: cybersecurityNews.com
Threat Score
**Executive Summary:** A sophisticated phishing campaign abuses Microsoft 365 organization display names and legitimate subscription/billing emails to embed credential-harvesting messages and direct victims to phone‑based scams; attackers create or compromise *.onmicrosoft.com tenants, set organization names to include fraudulent content, and send messages that pass SPF/DKIM/DMARC from Microsoft domains, greatly reducing detection by email security controls and recipients.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
