logo

Phishing actors exploit complex routing and misconfigurations to spoof domains

ID: 42516a98-5f41-5d94-8415-7196d81528c7

STIX ID: report--42516a98-5f41-5d94-8415-7196d81528c7

Feed Name: Microsoft Security

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft Threat Intelligence describes widespread phishing campaigns that abuse complex mail routing and improperly configured SPF/DMARC/DKIM or third-party connectors to spoof internal senders, delivering credential-phishing and invoice-fraud lures via PhaaS platforms (notably Tycoon2FA) and AiTM flows; the report includes header examples, IOCs, hunting queries, and mitigation/remediation guidance to prevent and respond to these attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.