Energy sector targeted in multi-stage phishing and BEC campaign using SharePoint
ID: c2a1d121-a929-56ca-87fc-d86fbb9bc35f
STIX ID: report--c2a1d121-a929-56ca-87fc-d86fbb9bc35f
Feed Name: Security Affairs
**Multi-stage AiTM phishing and BEC campaign targeting energy organizations:** Microsoft observed attackers using compromised trusted senders and SharePoint links to deliver AiTM (adversary-in-the-middle) phishing pages that captured credentials and session data. After compromising accounts, attackers created inbox rules to hide activity, sent over 600 phishing messages internally and externally, abused trusted accounts to expand reach, and conducted BEC by monitoring replies and removing warning emails. Microsoft recommends remediation beyond password resets — revoke sessions, remove malicious inbox rules, undo MFA changes, and enforce conditional access and advanced anti-phishing protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
