HomeSecurityMicrosoft 365: Phishing attacks abuse 'Direct Send'

Microsoft 365: Phishing attacks abuse 'Direct Send'

A new, sophisticated phishing campaign is once again bringing Microsoft 365 vulnerabilities to the fore , with cybercriminals exploiting the lesser-known “ Direct Send ” feature to bypass security systems and steal credentials.

Direct Send Microsoft 365 phishing

“Direct Send” allows on-premises devices, applications, or cloud servicesto send emails through a tenant’s smart host as if they were coming from the organization’s domain. It is designed for use by printers, scanners, and other devices that need to send messages on behalf of the company. While useful in controlled environments, its lack of security mechanisms makes it extremely attractive for malicious use, as it allows emails to be sent that appear to be “internal.” It requires no authentication, allowing remote users to send emails that look like internal messages from the company’s domain.

See also: Trezor: Phishing attack abuses customer support system

According to Microsoft, the feature should only be used by experienced administrators who are fully aware of the settings and risks involved. As the company notes, Direct Send is secure when Microsoft 365 is configured correctly and the smart host is properly locked down.

" We recommend Direct Send only to experienced customers who are willing to take on the responsibilities of email server admins ," Microsoft explains

At the same time, Microsoft has already shared instructions for disabling the feature, while considering its complete withdrawal from the Microsoft 365 platform in the future.

Phishing campaign exploits Direct Send: Targets critical US sectors

This particular phishing campaign was detected by the Varonis Managed Data Detection and Response (MDDR), which reports that more than 70 organizations have been targeted since May 2025. 95% of the victims are located in the United States, primarily in the Financial Services, Construction, Engineering, Healthcare, Manufacturing, and Insurance sectors.

PowerShell + Direct Send: The perfect hiding mechanism

The attacks are executed via PowerShell scripts, which use the target company's smart host (e.g. company-com.mail.protection.outlook.com) to send emails that look like internal messages.

This technique makes attacks particularly dangerous, as it allows attackers to bypass most modern filtering mechanisms.

An example of a PowerShell command that can send email through Microsoft 365's Direct Send feature is:

Send‑MailMessage -SmtpServer company‑com.mail.protection.outlook.com -To joe@company.com -From joe@company.com -Subject "New Missed Fax‑msg" -Body "You have received a call! Click on the link to listen to it. Listen Now" -BodyAsHtml

This method is effective because using Direct Send with the smart host does not require authentication and treats the sender as internal, allowing threat actors to bypass SPF, DKIM, DMARC rules, and other filtering rules.

Phishing messages appear as fake voicemail or fax notifications, with subjects such as “Caller Left VM Message.” The attached PDFs have titles such as “Fax Message,” “Play_VM-Now,” or “Listen,” luring users to phishing pages aimed at stealing login credentials.

Phishing via QR code

Instead of the usual links to malicious pages, the attached PDF files contain QR codes, which users are asked to scan with their phone's camera, supposedly to listen to a voice message. The presence of a company logo makes the content look authentic, increasing the chances of successful deception. Once the user scans the code, they are taken to a fake Microsoft 365 login page, designed to extract their credentials .

Varonis has released relevant Indicators of Compromise (IOCs), including domain names used in the campaign.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New TxTag phishing attack targets the .gov domain

Microsoft 365: Phishing attacks abuse 'Direct Send'

Dealing with Direct Send phishing – What experts recommend

To mitigate the threat, the researchers recommend enabling Reject Direct Send in the Exchange Admin Center. This option allows administrators to completely block emails coming through the Direct Send mechanism — especially if it is not essential to the organization's operations.

Varonis also recommends:

  • enable strict DMARC policy (e.g. p=reject)
  • quarantine or flag suspicious internal emails
  • enforce “SPF hardfail” in Exchange Online Protection
  • enable Anti-Spoofing policies
  • staff training to recognize QR phishing attacks

Don't assume internal emails are secure

“Direct Send can be useful, but in the wrong hands it can become a powerful cyberattack weapon,” Varonis warns. The company emphasizes the need for ongoing monitoring and updating of email security policies.

«If you are not actively monitoring spoofed internal emails or have not enabled the appropriate protections, now is the time to do so. Don't assume internal media is safe».

The abuse of Microsoft 365's “Direct Send” feature confirms that even seemingly innocent features can be turned into attack tools if not strictly controlled.

See also: Microsoft Outlook: Blocks other file types to prevent phishing

The above threat is particularly worrisome for many reasons – not only because of its technical complexity, but mainly because it exploits the human factor, i.e. the user’s curiosity and trust in “internal” messages. The emails appear to come from your own company, which increases the chances of them being opened or ignored by filters. This “internal” origin is what makes the threat so insidious.

This particular threat is a prime example of how cybercriminals don’t need to “break” systems – they just need to use them as designed, with a little more cunning. Organizations that don’t actively monitor their email infrastructure for vulnerabilities risk falling victim to attacks without even realizing it.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS