Microsoft Office 365 customers are being targeted by a phishing campaign that uses baited emailsthat appear to be notifications sent by their company, urging them to update VPN to access corporate data while working remotely. Phishing emails that appear to be requests to update their VPN configuration, supposedly sent by their company’s IT support department, have so far reached the inboxes of up to 15,000 targets, according to statistics from researchers at security Abnormal Security. These phishing emails are all the more dangerous because of the large percentage of employees who work remotely and use VPNs to connect to corporate resources from home, share documents with colleagues, and access corporate servers.

Specifically, attackers forge the sender’s email address in phishing emails to match the domains of their corporate targets and embed hyperlinks that, instead of directing recipients to new VPN configurations, send them to phishing sites designed to steal their Office 365 credentials . Abnormal Security said it has observed various variations of this attack on multiple customers, from different phishing email senders and from different IP addresses. However, all attacks used the same link payload , indicating that they were sent by a single attacker controlling the phishing site . These attacks could have a high success rate in deceiving potential victims, as many recipients might click through and log in to their Office 365 accounts to avoid losing remote access to company servers and files. The page that potential victims are directed to is a “cloned” Office 365 login page hosted on the Microsoft-owned web.core.windows.net domain, abusing Azure Blob Storage and accompanied by a valid Microsoft certificate, making the phishing attempt much more difficult to detect. Abusing the Azure Blob Storage platform to target Office 365 users is the perfect deception, seeing as the landing pages will automatically receive their own secure padlock page due to the wildcard SSL certificate *.web.core.windows.net.

Azure Blob Storage subdomains used in phishing pages are a well-known and very effective tactic that has been reported in the past. These phishing attacks can be easily countered if you configure custom Office 365 block rules to take advantage of the Office 365 ATP safe links feature to automatically block anything malicious. If you don’t configure block rules, the only way to make sure attackers don’t try to steal your credentials while entering them into an Office 365 sign-in form is to remember that the official sign-in pages are hosted by Microsoft on the microsoft.com, live.com, and outlook.com domains. Finally, last month, researchers at Abnormal Security discovered another highly convincing Office 365-based phishing campaign that used “cloned” images from automated Microsoft Teams that attempted to steal credentials from nearly 50,000 users.
