HomeSecurityMicrosoft: Incorrect email routing triggers internal domain phishing

Microsoft: Incorrect email routing enables internal domain phishing

Malicious actors involved in phishing exploit scripts routing and incorrect spoofingto mimic organizational domains and distribute emails that appear to have been sent internally.

email routing domain phishing

“ Malware actors have leveraged this channel to deliver a wide variety of phishing messages related to various phishing-as-a-service (PhaaS) platforms such as Tycoon 2FA ,” the Microsoft Threat Intelligence team said in a report. “ These include baited messages related to voicemails, shared documents, communications from human resources (HR) departments, password resets or expirations, and more, leading to credential theft .”

While the attack channel is not new, the tech giant said it has seen an increase in the use of the tactic since May 2025.

See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek

A successful attack could allow malicious actors to extract credentials and use them for subsequent activities, ranging from data theft to business email compromise (BEC).

Phishing attacks via Email Routing

The issue is most evident in scenarios where a tenant has configured a complex routing scenario and spoofing protections are not strictly enforced. An example of complex routing involves directing mail exchanger records (MX records) either to an on-premises Exchange environment or to a third-party service before reaching Microsoft 365.

Microsoft: Incorrect email routing enables internal domain phishing

This creates a security hole that attackers can exploit to send fake phishing emailsthat appear to come from the tenant's own domain. The vast majority of phishing campaigns that leverage this approach have been found to use the PhaaS kit Tycoon 2FA. Microsoft reported that it blocked more than 13 million malicious emails associated with the kit as of October 2025.

See also: Bug in Open WebUI turns 'free model' into a backdoor

Phishing kits

PhaaS tools are plug-and-play platforms that allow fraudsters to easily create and manage phishing campaigns. They provide features such as customizable phishing templates, infrastructure, and other tools to facilitate credential theft and authentication multi-factor through adversary-in-the-middle (AiTM) phishing.

Microsoft said it has also identified emails intended to trick organizations into paying false invoices, potentially leading to financial losses. The fake messages also mimic legitimate services like DocuSign or claim to be from HR regarding salary or benefits changes.

Microsoft: Incorrect email routing enables internal domain phishing

Phishing emails that spread financial scams often look like a conversation coming from the targeted organization's CEO or the company's accounting department. They also contain three attachments to give a false sense of trust:

– A fake invoice for thousands of dollars to be transferred to a bank account

– An IRS W-9 form stating the name and social security number of the person used to create the bank account

– A fake bank letter allegedly provided by an online bank employee (used to create the fake account)

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Kimwolf botnet abuses home proxy networks

“They may use clickable links in the body of the email or QR codes in attachments or other ways to lead the recipient to a phishing page,” the company added.

To address this risk, organizations are advised to set strict Domain-based Message Authentication, Reporting, and Conformance (DMARC) reject and Sender Policy Framework (SPF) hard fail policies and properly configure third-party links.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS