logo

Microsoft: Creative Abuse of Cloud Files Bolsters BEC Attacks

ID: 324754c9-25fb-55b9-b5d8-06c6131d2527

STIX ID: report--324754c9-25fb-55b9-b5d8-06c6131d2527

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-10-09

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Microsoft Threat Intelligence warns of a rise in sophisticated Business Email Compromise (BEC) campaigns that weaponize trusted cloud file-hosting services (Dropbox, OneDrive, SharePoint). Attackers compromise an initial enterprise account, host restricted or view-only files that bypass email and detonation protections, and lure trusted external recipients to authenticate—redirecting them to adversary-in-the-middle (AiTM) pages that capture credentials and MFA tokens. The compromised identities are then reused for financial fraud, data theft, lateral movement, and to deliver RATs/spyware; Microsoft recommends XDR and identity-focused monitoring to detect anomalous sign-ins and suspicious shared-file campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.