File hosting services misused for identity phishing
ID: dc1f8243-0207-5827-8d6f-6e7f38da2d33
STIX ID: report--dc1f8243-0207-5827-8d6f-6e7f38da2d33
Feed Name: Microsoft Security
Microsoft reports a rise in phishing campaigns abusing SharePoint, OneDrive, and Dropbox by sharing restricted-access, view-only files that bypass detonation, prompt re-auth/OTP, and redirect victims to AiTM pages to steal session tokens for BEC; the post outlines the end-to-end attack chain, highlights key defense-evasion TTPs, and provides concrete mitigations and hunting queries across Microsoft Defender and Sentinel to detect and disrupt these activities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
