Urgent.News

What's breaking now, across thousands of outlets.

Tech

Kaspersky flags Microsoft link phishing campaign

KUALA LUMPUR: Kaspersky has identified a phishing campaign exploiting legitimate Microsoft service links to redirect users to fraudulent websites or deliver malware.

Kaspersky flags Microsoft link phishing campaign

Kaspersky has uncovered a phishing campaign that leverages legitimate Microsoft service links to redirect users to fraudulent websites or deliver malware. The firm blocked over 31,000 emails containing these malicious links between August 1 and September 18. This latest operation builds upon a previous campaign where attackers exploited Microsoft's authentication mechanism to deceive victims.

In the new scam, cybercriminals craft emails that appear to be from Microsoft, prompting recipients to update their service credentials or sign electronic documents via embedded links. The attackers begin by creating a Microsoft account and registering a new application through the Microsoft Entra admin centre. They input a redirect URI, the address where Microsoft Entra sends users upon successful authentication.

Following this, the attackers embed the malicious website's address into the redirect URI field and spread Microsoft redirect links containing the application ID and specified URI. Clicking such links leads users to deceitful websites designed to pilfer personal data or install malware.

Furthermore, Kaspersky discovered that attackers can utilize Microsoft Entra to embed false content into genuine service notifications. They create fictitious user accounts with fabricated email addresses, names, and passwords, subsequently registering the victim's actual email address as a backup mailbox for password reset messages. Consequently, the victim receives an unsolicited verification code, while the criminals' fraudulent message appears in the email subject and signature.

Andrey Kovtun, Kaspersky's email threats protection group manager, stated that employing legitimate services enhances the scams' credibility, making them harder to detect. He emphasized that this tactic adds a dangerous layer of authenticity, rendering the scam more difficult to spot. Kovtun recommended that users deploy security solutions with strong anti-phishing capabilities, especially as conventional phishing signs may not apply to these attacks.

Organizations are advised to consider email security solutions capable of identifying advanced mail-borne threats, as cybercriminals are increasingly exploiting legitimate platforms and services.

Written by urgent.news from New Straits Times's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at nst.com.my →

More in Tech

More from Wednesday 7 October →