Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign
ID: ec9c1792-662d-530b-9109-2518c5ef9284
STIX ID: report--ec9c1792-662d-530b-9109-2518c5ef9284
Feed Name: cybersecurityNews.com
Microsoft Defender disclosed a sophisticated AiTM phishing campaign targeting energy sector organisations by abusing SharePoint links from a compromised vendor account to harvest credentials and session cookies, then establishing persistence (malicious inbox rules, MFA manipulation) and conducting mass BEC operations across multiple organisations; Microsoft published two IP IoCs and recommended revoking session cookies, removing inbox rules, resetting MFA, and implementing conditional access and advanced anti-phishing defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
