Hackers have come up with a new method to trick users via email. In this new phishing campaign, hackers have created a fake page that is supposed to be a list of emails that have not been delivered to the user for some reason. This page gives the user the impression that the emails have been stored in the Outlook Web Mail service.
Essentially, users are asked to decide what to do with each of these emails. The links, which are available, lead to a fake login page.
Scamming victims via email is very common. Hackers are constantly developing new methods of exploiting emails. Recently, there was a campaign where users received notifications about their account being canceled. In another case, users found notifications about file deletion.
In the new phishing campaign, victims find a notification that reads: “Undelivered emails in your Inbox” and displays a list of emails that are supposedly kept stored on your server.
As mentioned above, users are asked to decide what to do with these emails. The options they have are to delete the emails, allow their delivery, reject them, or add them to a whitelist. Whichever option they choose, whichever link they click, they will be taken to a fake “Outlook Web App” page, which asks them to enter their credentials to log in.
From the moment the credentials are entered, the page stores them and thus hackers will have access to them.
Unlike other fake pages, which are hosted on Excel Online or Microsoft Azure, this particular page is hosted on a hacked site. This is good, because if we pay attention to the URL, we can see that it is something suspicious and therefore avoid it.
When we are taken to a login page where we need to enter our credentials, we should double check the URL. If there is any doubt, we should always contact our system administrators.
