A sophisticated Double-Edged Emailuses a dual-threat approach to steal Microsoft Office365 and deliver malware to unsuspecting victims.
See also: Malicious OAuth applications target Microsoft 365 accounts

This hybrid attack begins with deceptive emails pretending to be reminders to delete files from legitimate file sharing services, creating a false sense of urgency that forces users to act immediately to preserve supposedly important documents.
The attack skillfully exploits users' trust, using the cloud storage platform files.fm as the initial delivery mechanism.
Recipients receive warnings about impending file deletions with themes referring to business documents, prompting them to click on document name hyperlinks that direct them to real files.fm pages. This approach significantly enhances the credibility of the attack, as users are interacting with a genuine file sharing service early in the infection chain.
Researchers at the Cofense Phishing Defense Center (PDC) spotted this campaign and noticed its particularly insidious “pick your poison” approach.
After downloading and opening the shared PDF file, users see two seemingly innocent options: “Preview” or “Download” – each of which leads to different but equally harmful results.
See also: Microsoft 365 outage removes web apps
This split attack strategy maximizes success rates by offering multiple paths to breach.

The credential collection process is triggered when users select the “Preview” option. This action redirects victims to a convincing but fake Microsoft login page, which closely mimics the authentic interface.
The page, while featuring familiar Microsoft branding , has subtle inconsistencies, such as non-Microsoft URLs . However, these warning signs are often overlooked at the time, resulting in stolen credentials when users try to log in.
Alternatively, selecting “ Download ” triggers the installation of malware that pretends to be “ SecuredOneDrive.ClientSetup.exe .” This executable pretends to be legitimate Microsoft software, while in reality it installs the ConnectWise RAT (Remote Access Trojan), a malicious tool that exploits legitimate remote administration software for unauthorized system access
See also: Microsoft Office 2024 disables ActiveX by default
Double-Edged Email attack refers to a cyberattack strategy that exploits the use of email to deceive and attack an organization or individual. Essentially, this attack involves two parts: the sending of a Malicious or Infected Email and the expected Response . The double-edged nature of the attack stems from the idea that the malicious action (sending the email) can be twice as dangerous to the victim: once for the initial email and once for the potential counterattack or exploitation after the email is accepted. Countering this type of attack requires increased attention from users and companies, such as the use of strong spam filters and training users to recognize dangerous emails.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
