Ongoing Microsoft Azure account hijacking campaign targets executives
ID: 8252bfec-61ab-5445-8a86-9b6c51acf5f0
STIX ID: report--8252bfec-61ab-5445-8a86-9b6c51acf5f0
Feed Name: Bleeping Computer
Proofpoint detected a late-November 2023 phishing campaign that has compromised hundreds of Microsoft Azure / Microsoft 365 user accounts — including senior executives — by luring victims with documents linking to phishing pages. Attackers use a Linux Chrome user-agent (Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36), target Office365 components (Exchange Online, My Signins, My Apps, My Profile, Office365 Shell), and perform MFA manipulation, data exfiltration, internal/external phishing, and financial fraud; Proofpoint recommends monitoring the user-agent and source domains, resetting compromised passwords, deploying account-takeover detection, enforcing anti-phishing protections, and automating threat response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
