logo

Hackers Leverage Microsoft 365’s Direct Send Feature to Launch Internal Phishing Attacks

ID: 659feadf-720c-57c0-b761-94ad746db613

STIX ID: report--659feadf-720c-57c0-b761-94ad746db613

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2025-08-02

Date Updated: 2026-04-13

Author: Priya

...
...

Proofpoint researchers identified a phishing campaign that exploits Microsoft 365 Direct Send to send emails that appear to originate from within targeted organizations by relaying messages through attacker‑controlled Windows Server 2022 hosts and compromised third‑party email appliances; the report includes IOCs (several IPs and a self‑signed certificate CN), sample lure subjects, and remediation guidance (audit Direct Send usage, enable RejectDirectSend, and enforce SPF/DKIM/DMARC).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.