logo

File hosting services misused for identity phishing

ID: dc1f8243-0207-5827-8d6f-6e7f38da2d33

STIX ID: report--dc1f8243-0207-5827-8d6f-6e7f38da2d33

Feed Name: Microsoft Security

Date Published: 2024-10-08

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence

...
...

Microsoft reports a rise in phishing campaigns abusing SharePoint, OneDrive, and Dropbox by sharing restricted-access, view-only files that bypass detonation, prompt re-auth/OTP, and redirect victims to AiTM pages to steal session tokens for BEC; the post outlines the end-to-end attack chain, highlights key defense-evasion TTPs, and provides concrete mitigations and hunting queries across Microsoft Defender and Sentinel to detect and disrupt these activities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.