HomeSecurityMalicious website hosts phishing Outlook Web App website

Malicious website hosts phishing Outlook Web App webpage

A Russian website designed for spear- phishing attacks has been compromised to host a phishing page that seeks to capture Outlook Web App log-in credentials .

Outlook Web App Phishing Page

Security researchers who observed this activity discovered that the attack targeted email recipients at universities and was based on a very plausible but malicious website with the aim of deceiving unsuspecting students, faculty, or staff working at targeted educational institutions.

One difference that can be observed between the fake login page and the real one is that the malicious website contains a field for entering the email address, while a legitimate log-in session only requires the account username and password.

It is important to note that the login credentials in many cases are the same and are used to access users' accounts other than their Outlook. Proofpoint says that even if just one user is compromised, the attacker could gain valuable information and potentially access other resources. This way, the attacker could move laterally through the network and gain access to financial information or data that is part of a scientific study.

The security firm did not mention the "bait" included in the phishing e-mail, but rather took into account the quality of the malicious website.

Users should always check the URL of a log-in page before entering sensitive information, especially when the link comes via email from an untrusted source.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS