logo

Ongoing Microsoft Azure account hijacking campaign targets executives

ID: 8252bfec-61ab-5445-8a86-9b6c51acf5f0

STIX ID: report--8252bfec-61ab-5445-8a86-9b6c51acf5f0

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-02-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint detected a late-November 2023 phishing campaign that has compromised hundreds of Microsoft Azure / Microsoft 365 user accounts — including senior executives — by luring victims with documents linking to phishing pages. Attackers use a Linux Chrome user-agent (Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36), target Office365 components (Exchange Online, My Signins, My Apps, My Profile, Office365 Shell), and perform MFA manipulation, data exfiltration, internal/external phishing, and financial fraud; Proofpoint recommends monitoring the user-agent and source domains, resetting compromised passwords, deploying account-takeover detection, enforcing anti-phishing protections, and automating threat response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.