Security experts are warning of a new phishing that targets Office 365 administrators and uses valid domains to bypass spam filters.
PhishLabs stated that it saw malicious emails being sent as part of the campaign across a wide range of industries and businesses, and the reasons why the victims are targeted are varied.

“For starters, Office 365 administrators have administrative control over all email in a domain. Depending on the current configuration of Office 365, a compromised administrator account could be used to recover a user’s emails or take full control of other email accounts in that domain,” said a PhishLabs spokesperson.
“Furthermore, Office 365 administrators often have elevated privileges on other systems within an organization, potentially allowing further breaches to occur through password reset attempts or abuse of single-sign-on systems.”
Once an administrator is deleted, attackers are able to create new accounts, which are then used to send more fraudulent phishing emails.
By creating new accounts to conduct this phishing activity, hackers have a better chance of staying under the radar.

These phishing scams look like regular emails sent by Microsoft – for example, a message asking the recipient to log in to the Office 365 admin center to update payment information.
Finally, Office 365 continues to grow in popularity among users and consequently among hackers as well. Barracuda Networks discovered over 1.5 million malicious and unwanted emails being sent from thousands of malicious accounts in just a month earlier this year.
