logo

Direct Send: How Attackers Weaponize Your Infrastructure Against You

ID: 3b791710-8f17-51dd-9912-dbb898cff309

STIX ID: report--3b791710-8f17-51dd-9912-dbb898cff309

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2026-09-10

Date Updated: 2026-09-10

Author: KnowBe4 Threat Lab

...
...

**Executive summary:** KnowBe4 Threat Labs observed a large Direct Send abuse campaign (≈29,785 confirmed spoofs in Jul–Aug 2026) that leverages Exchange Online's open MX endpoint to send unauthenticated emails appearing from internal addresses. Attackers used social-engineering lures (fake docs, voicemail alerts, invoices, OneDrive links) timed to business hours, rotated cloud providers, and employed reply-to mismatches and redirecting .url files to harvest credentials and enable BEC; the report includes IOCs, header indicators (X-MS-Exchange-Organization-AuthAs:Anonymous), and actionable Microsoft 365 configuration fixes such as enforcing DMARC, locking inbound connectors, and DKIM.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.