Thwarting Financial Fraud: Shutting Down Hackers in Microsoft 365
ID: fc1cd697-7ae2-51d1-9439-47a0b9dfe2a9
STIX ID: report--fc1cd697-7ae2-51d1-9439-47a0b9dfe2a9
Feed Name: Huntress Blog
Huntress recounts a BEC incident targeting a US logistics company where attackers used compromised Microsoft 365 credentials from Nigerian IP addresses to create inbox rules (e.g., moving mail to Conversation History and marking as read) and forwarding to intercept vendor invoices and attempt fund diversion; the SOC detected and stopped the activity. The report provides IoCs (IPs and rule names), highlights T1078.004 (valid cloud accounts), and advises monitoring for short nonsensical inbox rule names and rules that move mail to seldom-used folders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
