logo

Thwarting Financial Fraud: Shutting Down Hackers in Microsoft 365

ID: fc1cd697-7ae2-51d1-9439-47a0b9dfe2a9

STIX ID: report--fc1cd697-7ae2-51d1-9439-47a0b9dfe2a9

Feed Name: Huntress Blog

Threat Score
60/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress recounts a BEC incident targeting a US logistics company where attackers used compromised Microsoft 365 credentials from Nigerian IP addresses to create inbox rules (e.g., moving mail to Conversation History and marking as read) and forwarding to intercept vendor invoices and attempt fund diversion; the SOC detected and stopped the activity. The report provides IoCs (IPs and rule names), highlights T1078.004 (valid cloud accounts), and advises monitoring for short nonsensical inbox rule names and rules that move mail to seldom-used folders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.