Microsoft: Creative Abuse of Cloud Files Bolsters BEC Attacks
ID: 324754c9-25fb-55b9-b5d8-06c6131d2527
STIX ID: report--324754c9-25fb-55b9-b5d8-06c6131d2527
Feed Name: Dark Reading
Date Published: 2024-10-09
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Microsoft Threat Intelligence warns of a rise in sophisticated Business Email Compromise (BEC) campaigns that weaponize trusted cloud file-hosting services (Dropbox, OneDrive, SharePoint). Attackers compromise an initial enterprise account, host restricted or view-only files that bypass email and detonation protections, and lure trusted external recipients to authenticate—redirecting them to adversary-in-the-middle (AiTM) pages that capture credentials and MFA tokens. The compromised identities are then reused for financial fraud, data theft, lateral movement, and to deliver RATs/spyware; Microsoft recommends XDR and identity-focused monitoring to detect anomalous sign-ins and suspicious shared-file campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
