logo

New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft

ID: f2d7b1fc-7b9d-5089-bf1a-35ad87141e8d

STIX ID: report--f2d7b1fc-7b9d-5089-bf1a-35ad87141e8d

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-10-18

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** Threat actors are abusing Microsoft Azure Blob Storage to host highly convincing phishing pages that impersonate Office 365 sign-in portals, tricking users into submitting Microsoft 365 credentials; the campaign often begins with deceptive emails (e.g., Forms links) and redirects to HTML hosted under blob.core.windows.net, making the pages appear legitimate and SSL-secured. The report highlights indicators (blob.core.windows.net URLs), the risk of credential and tenant compromise, and recommends mitigations including blocking *.blob.core.windows.net except trusted accounts, enabling MFA, monitoring Microsoft Entra ID for anomalous logins, and applying custom tenant branding to help users identify genuine sign-ins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.