logo

Microsoft Azure Monitor alerts abused for callback phishing attacks

ID: 97a94159-5fb6-562c-b777-450677102e5b

STIX ID: report--97a94159-5fb6-562c-b777-450677102e5b

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-03-21

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Microsoft Azure Monitor alerts are being abused in a callback phishing campaign where attackers create alert rules with fraudulent billing messages and phone numbers; because the alerts originate from [email protected] they pass SPF/DKIM/DMARC checks and bypass spam filters. Targets receive urgent invoice/payment notifications (e.g., a $389 Windows Defender charge) urging them to call listed numbers, which can lead to credential theft, financial fraud, or remote access compromise and may be used to gain initial access to corporate networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.