Hackers Leverage Microsoft 365’s Direct Send Feature to Launch Internal Phishing Attacks
ID: 659feadf-720c-57c0-b761-94ad746db613
STIX ID: report--659feadf-720c-57c0-b761-94ad746db613
Feed Name: Cyber Press
Threat Score
Proofpoint researchers identified a phishing campaign that exploits Microsoft 365 Direct Send to send emails that appear to originate from within targeted organizations by relaying messages through attacker‑controlled Windows Server 2022 hosts and compromised third‑party email appliances; the report includes IOCs (several IPs and a self‑signed certificate CN), sample lure subjects, and remediation guidance (audit Direct Send usage, enable RejectDirectSend, and enforce SPF/DKIM/DMARC).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
