A new, sophisticated phishing campaign is once again bringing Microsoft 365 vulnerabilities to the fore , with cybercriminals exploiting the lesser-known “ Direct Send ” feature to bypass security systems and steal credentials.

“Direct Send” allows on-premises devices, applications, or cloud servicesto send emails through a tenant’s smart host as if they were coming from the organization’s domain. It is designed for use by printers, scanners, and other devices that need to send messages on behalf of the company. While useful in controlled environments, its lack of security mechanisms makes it extremely attractive for malicious use, as it allows emails to be sent that appear to be “internal.” It requires no authentication, allowing remote users to send emails that look like internal messages from the company’s domain.
See also: Trezor: Phishing attack abuses customer support system
According to Microsoft, the feature should only be used by experienced administrators who are fully aware of the settings and risks involved. As the company notes, Direct Send is secure when Microsoft 365 is configured correctly and the smart host is properly locked down.
" We recommend Direct Send only to experienced customers who are willing to take on the responsibilities of email server admins ," Microsoft explains
At the same time, Microsoft has already shared instructions for disabling the feature, while considering its complete withdrawal from the Microsoft 365 platform in the future.
Phishing campaign exploits Direct Send: Targets critical US sectors
This particular phishing campaign was detected by the Varonis Managed Data Detection and Response (MDDR), which reports that more than 70 organizations have been targeted since May 2025. 95% of the victims are located in the United States, primarily in the Financial Services, Construction, Engineering, Healthcare, Manufacturing, and Insurance sectors.
PowerShell + Direct Send: The perfect hiding mechanism
The attacks are executed via PowerShell scripts, which use the target company's smart host (e.g. company-com.mail.protection.outlook.com) to send emails that look like internal messages.
This technique makes attacks particularly dangerous, as it allows attackers to bypass most modern filtering mechanisms.
An example of a PowerShell command that can send email through Microsoft 365's Direct Send feature is:
Send‑MailMessage -SmtpServer company‑com.mail.protection.outlook.com -To joe@company.com -From joe@company.com -Subject "New Missed Fax‑msg" -Body "You have received a call! Click on the link to listen to it. Listen Now" -BodyAsHtmlThis method is effective because using Direct Send with the smart host does not require authentication and treats the sender as internal, allowing threat actors to bypass SPF, DKIM, DMARC rules, and other filtering rules.
Phishing messages appear as fake voicemail or fax notifications, with subjects such as “Caller Left VM Message.” The attached PDFs have titles such as “Fax Message,” “Play_VM-Now,” or “Listen,” luring users to phishing pages aimed at stealing login credentials.
Phishing via QR code
Instead of the usual links to malicious pages, the attached PDF files contain QR codes, which users are asked to scan with their phone's camera, supposedly to listen to a voice message. The presence of a company logo makes the content look authentic, increasing the chances of successful deception. Once the user scans the code, they are taken to a fake Microsoft 365 login page, designed to extract their credentials .
Varonis has released relevant Indicators of Compromise (IOCs), including domain names used in the campaign.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: New TxTag phishing attack targets the .gov domain

Dealing with Direct Send phishing – What experts recommend
To mitigate the threat, the researchers recommend enabling Reject Direct Send in the Exchange Admin Center. This option allows administrators to completely block emails coming through the Direct Send mechanism — especially if it is not essential to the organization's operations.
Varonis also recommends:
- enable strict DMARC policy (e.g.
p=reject) - quarantine or flag suspicious internal emails
- enforce “SPF hardfail” in Exchange Online Protection
- enable Anti-Spoofing policies
- staff training to recognize QR phishing attacks
Don't assume internal emails are secure
“Direct Send can be useful, but in the wrong hands it can become a powerful cyberattack weapon,” Varonis warns. The company emphasizes the need for ongoing monitoring and updating of email security policies.
«If you are not actively monitoring spoofed internal emails or have not enabled the appropriate protections, now is the time to do so. Don't assume internal media is safe».
The abuse of Microsoft 365's “Direct Send” feature confirms that even seemingly innocent features can be turned into attack tools if not strictly controlled.
See also: Microsoft Outlook: Blocks other file types to prevent phishing
The above threat is particularly worrisome for many reasons – not only because of its technical complexity, but mainly because it exploits the human factor, i.e. the user’s curiosity and trust in “internal” messages. The emails appear to come from your own company, which increases the chances of them being opened or ignored by filters. This “internal” origin is what makes the threat so insidious.
This particular threat is a prime example of how cybercriminals don’t need to “break” systems – they just need to use them as designed, with a little more cunning. Organizations that don’t actively monitor their email infrastructure for vulnerabilities risk falling victim to attacks without even realizing it.
Source: www.bleepingcomputer.com
