Cisco experts discovered a phishing campaign that is spreading fake Volume License Trojan Chanitor to corporate users and is able to evade sandboxes. The malicious mails are tailored for each customer and inform Microsoft customers they have been assigned new licenses for free, its recipient seems to be a Microsoft account. The attack aims to compromise corporate users, when victims click on the link included in the email they are redirected to the Microsoft Volume Licensing Service Center (VLSC) login page. In reality the malicious link triggered the execution of a Javascript function that displays users the real Microsoft Volume License Center login page and starts a download of the fake volume license.”]
Source: https://securityaffairs.co/wordpress/33325/cyber-crime/volume-license-trojan-chanitor.html