logo

Direct Send abuse on Microsoft 365: Just another failed authentication · Blog · Sublime Security

ID: 9c96ebda-7bb8-5930-bbd9-d79e72235a11

STIX ID: report--9c96ebda-7bb8-5930-bbd9-d79e72235a11

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2025-12-18

Date Updated: 2026-05-01

...
...

Sublime's Attack Spotlight analyzes two live phishing campaigns abusing Microsoft 365 Direct Send—one using a DOCX with a QR code that redirects to credential-phishing pages, and another using an SVG with embedded JavaScript and multilayer Base64 that redirects to a credential harvester—highlighting detection signals (failed SPF/DMARC, self-sender, empty body, base64, JS smuggling) and demonstrating how Sublime’s AI/ML and file-analysis capabilities block these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.