Cybercriminals are behind a phishing campaignthat uses cybersecurity firm Proofpoint to trick users into giving them credentials for Microsoft Office 365 and Gmail. The phishing email has the subject line “Re: Payoff Request.”
See also: Phishing emails infect victims with MirCop ransomware

“ The email claimed to contain a secure file, sent via Proofpoint, as a link ,” Armorblox wrote in a post . “ By clicking on the link, victims are taken to a Proofpoint-branded page, which contains login links for different email providers .”
See also: Mobile phishing attacks: 161% increase against the energy sector
The phishing email was sent from a compromised email of a legitimate user. The sender's domain (sdis34[.]fr) was a fire department in the South of France.

By clicking on the Google and Office 365 buttons, victims are taken to specially crafted Google and Microsoft phishing pages, which ask for credentials.
See also: DocuSign phishing campaign targets low-ranking employees
The phishing campaign techniques used by Proofpoint to convince victims to give up their credentials:
Social engineering: The email’s title and content were intended to create a sense of trust, but also a sense of urgency. Trust was created because the email claimed to contain a file sent via Proofpoint. As for the urgency, the email referred to loan-related issues, so victims needed to take immediate action.
Impersonation of company names: The email and landing page used Proofpoint to make the message appear more legitimate. The criminals also created seemingly legitimate login pages for Google Workspace and Office 365.
Using a compromised email address: The email was sent from a compromised email account of an individual belonging to a French fire department.
Source: securityaffairs.co
