logo

Energy sector targeted in multi-stage phishing and BEC campaign using SharePoint

ID: c2a1d121-a929-56ca-87fc-d86fbb9bc35f

STIX ID: report--c2a1d121-a929-56ca-87fc-d86fbb9bc35f

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

**Multi-stage AiTM phishing and BEC campaign targeting energy organizations:** Microsoft observed attackers using compromised trusted senders and SharePoint links to deliver AiTM (adversary-in-the-middle) phishing pages that captured credentials and session data. After compromising accounts, attackers created inbox rules to hide activity, sent over 600 phishing messages internally and externally, abused trusted accounts to expand reach, and conducted BEC by monitoring replies and removing warning emails. Microsoft recommends remediation beyond password resets — revoke sessions, remove malicious inbox rules, undo MFA changes, and enforce conditional access and advanced anti-phishing protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.