A Russian website designed for spear- phishing attacks has been compromised to host a phishing page that seeks to capture Outlook Web App log-in credentials .
Security researchers who observed this activity discovered that the attack targeted email recipients at universities and was based on a very plausible but malicious website with the aim of deceiving unsuspecting students, faculty, or staff working at targeted educational institutions.
One difference that can be observed between the fake login page and the real one is that the malicious website contains a field for entering the email address, while a legitimate log-in session only requires the account username and password.
It is important to note that the login credentials in many cases are the same and are used to access users' accounts other than their Outlook. Proofpoint says that even if just one user is compromised, the attacker could gain valuable information and potentially access other resources. This way, the attacker could move laterally through the network and gain access to financial information or data that is part of a scientific study.
The security firm did not mention the "bait" included in the phishing e-mail, but rather took into account the quality of the malicious website.
Users should always check the URL of a log-in page before entering sensitive information, especially when the link comes via email from an untrusted source.

