Microsoft Sway abused in massive QR code phishing campaign
ID: 767029d6-14a5-5e20-8ee6-e219ace9545a
STIX ID: report--767029d6-14a5-5e20-8ee6-e219ace9545a
Feed Name: Bleeping Computer
Netskope Threat Labs observed a massive QR-code-based phishing campaign in July 2024 that abused Microsoft Sway to host landing pages designed to harvest Microsoft 365 credentials and MFA codes. The attackers embedded phishing URLs in QR images to evade text-based email scanners and push victims to mobile devices, used Cloudflare Turnstile to maintain domain reputation and avoid blocking, and applied transparent phishing to sign victims into their accounts while displaying legitimate pages; primary targets were organizations in Asia and North America across technology, manufacturing, and finance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
