Attackers Impersonate Microsoft Services To Target Customers

Attackers are actively impersonating Microsoft services to target customers with Microsoft, Office 365, Outlook, and OneDrive accounts.

The campaign was discovered by a security researcher, MalwareHunterTeam. According to the researcher, attackers could fake the custom branding and web hosting features to host static landing phishing sites.

Misused platforms include Microsoft Azure’s Static Web Apps which is used to steal Microsoft, Office 365, Outlook and OneDrive credentials.

While the fake landing pages can be used to scam Microsoft customers, they could also be used to target users of other platforms such as Rackspace, AOL, Yahoo and other email providers.

Users are often advised to check URLs when prompted to fill in their account details in a login form.

However, this advice is almost pointless in this scenario, as users are deceived by the subdomain and the valid TLS certificate.

IT World Canada Staff
IT World Canada Staff
The online resource for Canadian Information Technology professionals.

Would you recommend this article?


Thanks for taking the time to let us know what you think of this article!
We'd love to hear your opinion about this or any other story you read in our publication.

Jim Love, Chief Content Officer, IT World Canada

Featured Download

ITW in your inbox

Our experienced team of journalists and bloggers bring you engaging in-depth interviews, videos and content targeted to IT professionals and line-of-business executives.

More Best of The Web