logo

Microsoft Warns of Surge in Internal Domain Spoofing

ID: 08e8aa10-1222-5b1b-8717-19aa5ad6d54b

STIX ID: report--08e8aa10-1222-5b1b-8717-19aa5ad6d54b

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

Microsoft Threat Intelligence reports a surge in sophisticated phishing campaigns that exploit complex mail routing and misconfigured spoof protections to spoof internal domains and deliver convincing phishing emails. Attackers are using the Tycoon2FA Phishing-as-a-Service platform to perform AiTM/MFA-bypass attacks, resulting in credential theft and targeted financial fraud; Microsoft recommends enforcing strict DMARC/SPF policies and properly configuring third-party connectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.