Microsoft Azure Monitor alerts abused for callback phishing attacks
ID: 97a94159-5fb6-562c-b777-450677102e5b
STIX ID: report--97a94159-5fb6-562c-b777-450677102e5b
Feed Name: Bleeping Computer
Microsoft Azure Monitor alerts are being abused in a callback phishing campaign where attackers create alert rules with fraudulent billing messages and phone numbers; because the alerts originate from [email protected] they pass SPF/DKIM/DMARC checks and bypass spam filters. Targets receive urgent invoice/payment notifications (e.g., a $389 Windows Defender charge) urging them to call listed numbers, which can lead to credential theft, financial fraud, or remote access compromise and may be used to gain initial access to corporate networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
