Microsoft Cloud Users Fall Prey to Sophisticated Phishing Campaign
A highly sophisticated phishing campaign has been targeting Microsoft Cloud users, compromising their accounts and stealing sensitive files. The attackers use pre-attack research to gather information about employees and organizational structure from public sources such as social networking and professional profiling platforms.
The attack begins with a phone call, where victims are told they need to update their passkey (or MFA) immediately to avoid disruptions to their operations. A follow-up SMS is then sent with a link to update the security configuration, which appears to be the legitimate Microsoft login landing page but is actually a pre-built malicious website using adversary-in-the-middle (AitM) techniques.
The actors seem to invest heavily in pre-attack research and may also take advantage of already compromised accounts to expand their reach. The campaign has been ongoing since at least May this year, with the goal of exfiltrating files from SharePoint and OneDrive, as well as email data from Microsoft Exchange Online.