HomeSecurityMicrosoft: "Closes" 6 domains related to phishing businesses

Microsoft: “Closes” 6 domains associated with phishing businesses

Microsoft

Microsoft court order this month that allows the company to shut down six domains that were used in phishing campaigns against Office 365 users. Many of the phishing emails included topics related to COVID-19.

According to court documents, Microsoft has been targeting a phishing group that has been attacking the company's customers since December 2019.

The phishing emails were designed to appear authentic. They were supposed to come from fellow employees or a trusted business partner. This particular phishing operation was unique because the attackers did not attempt to redirect users to phishing sites that mimicked the Office 365.

Instead, the hackers had embedded an Office document. When users tried to open the file, they were prompted to install a malicious application Office 365 created by the attackers.

Installing the application allowed hackers to gain full access to the victim's Office 365 account, its settings, the user's files, the content of their emails, contact lists, notes, and more.

Microsoft said that with this malicious Office 365 application, hackers gained full access to accounts, without the need to collect passwords.

Some of these phishing attacks were successful for three reasons. The first reason is that the application was designed to appear to be created by Microsoft and to be secure.

The second reason has to do with the Office 365 environment itself. Users are used to downloading applications third-party. Therefore, they didn't realize that anything strange was happening.

Finally, the hackers used a clever technique. Initially, users were taken to the official Microsoft login page. The application would appear after authentication, giving users the impression that they were using an application controlled by Microsoft.

In agreement with the court, Microsoft targeted six domains where hackers were hosting the malicious Office 365 applications. The 6 domains are listed below:

phishing

Microsoft believes at least two individuals are behind this phishing operation. The company noted that the initial attacks used business-related themes, but quickly switched to COVID-19-themed emails.

' ultimate goal was to carry out BEC attacks

Tom Burt, a key Microsoft executive, said the malicious applications were used to obtain information that would allow hackers to continue with BEC (business email compromise) attacks.

In these attacks, attackers send emails, posing as employees, senior executives or trusted business associates, and ask victims to make transactions that end up in the attacker's bank accounts.

The FBI has stated that BEC scams were one of the most significant threats in 2019.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS