Blog | G5 Cyber Security

Phishing Campaign Used Fake Office 365 Update Messages

Phishing campaign used fake Microsoft Office 365 update messages to target financial executives and others. Security firm Area 1 says it identified 100 targeted individuals across 40 companies. The attackers used malware to bypass Microsoft’s native email defenses and authentication processes. They used Microsoft-themed sender domains, which enabled them to bypass email authentication using PDF/HTM/ HTML attachments. The campaign used nine domains; four were fakes, while the others were compromised legitimate URLs, the researchers say. Area 1 describes the attackers’ phishing kit as highly advanced.”]

Source: https://www.govinfosecurity.com/phishing-campaign-used-fake-office-365-update-messages-a-16261

Exit mobile version