Trusted Sender, Wrong Identity: How a Compromised Vendor Account Delivered a Microsoft Sway Credential Harvest
ID: 7db83be6-f4ad-5e77-b2dc-ca2e7df544c0
STIX ID: report--7db83be6-f4ad-5e77-b2dc-ca2e7df544c0
Feed Name: IRONSCALES
Attackers compromised a vendor's Microsoft-hosted email account and sent image-only, BCC-distributed spearphishing messages impersonating a Fortune 500 hospitality company; the messages passed SPF/DKIM/DMARC and pushed victims to credential-harvesting pages hosted on Microsoft Sway (sway.office.com / sway.cloud.microsoft). Indicators include sending IPs 4.36.33.107 and 20.83.171.190 and the Sway URLs; the report recommends auditing vendor authentication, treating trusted productivity URLs with skepticism, flagging image-only mail from first-time senders, and monitoring header recipient mismatches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
