Microsoft’s Azure Phishing Attacks
ID: 7e154362-4914-5bf1-989c-501748749302
STIX ID: report--7e154362-4914-5bf1-989c-501748749302
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabZ documented active phishing campaigns that leveraged Microsoft Azure-hosted domains and Microsoft-signed SSL certificates to host credential-harvesting pages (Outlook, OneDrive, Adobe, blockchain themes). Attackers delivered lures via spam (links and malicious HTML attachments), used obfuscated JavaScript to validate and exfiltrate credentials to attacker-controlled Azure endpoints, and Zscaler blocked over 2,000 phishing attempts in six weeks; the report includes numerous Azure web/Blob IOCs and remediation/takedown coordination with Microsoft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
