logo

Microsoft’s Azure Phishing Attacks

ID: 7e154362-4914-5bf1-989c-501748749302

STIX ID: report--7e154362-4914-5bf1-989c-501748749302

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ documented active phishing campaigns that leveraged Microsoft Azure-hosted domains and Microsoft-signed SSL certificates to host credential-harvesting pages (Outlook, OneDrive, Adobe, blockchain themes). Attackers delivered lures via spam (links and malicious HTML attachments), used obfuscated JavaScript to validate and exfiltrate credentials to attacker-controlled Azure endpoints, and Zscaler blocked over 2,000 phishing attempts in six weeks; the report includes numerous Azure web/Blob IOCs and remediation/takedown coordination with Microsoft.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.