Microsoft Sway Abused in Office 365 Phishing Attack
#1
Information 
Quote:A highly targeted phishing campaign, with a Microsoft file platform twist, has successfully siphoned the Office 365 credentials of more than 150 executives since mid-2019.
 
Researchers attribute the campaign’s success to two parts: First, it leverages multiple Microsoft file-sharing services to convince victims to hand over their credentials. That includes Microsoft’s Sway platform used for newsletters and presentations (its use of Sway, in fact, inspired researchers to name the campaign “PerSwaysion”), as well as the SharePoint and OneNote collaboration platforms. Second, the initial phishing emails are sent from legitimate but previously compromised email addresses — which cloak the fact that they’re attacker-controlled.
 
Multiple threat groups are working together to carry out PerSwaysion, according to researchers.
“PerSwaysion campaign is yet another living example of highly specialized phishing threat actors working together to conduct effective attacks on a large scale,” said Feixiang He, senior threat intelligence analyst at Group-IB in a Thursday analysis.” The campaign phishing kit is primarily developed by a group of Vietnamese-speaking malware developers, while campaign proliferation and hacking activities are operated by other independent groups of scammers.”
 
The ongoing PerSwaysion campaign has targeted small- and medium-sized financial services companies, law firms and real estate groups across the U.S., Canada, Germany, the U.K. and other countries. Its impact is serious: Access to executives’ Office 365 accounts gives attackers a full range of top-level, sensitive corporate data, as well as the ability to launch subsequent phishing attacks on other high-profile targets.

Read more: https://threatpost.com/microsoft-sway-ab...ck/155366/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19
JEDEC publishes UFS 5.0 spec with up to ...
KIOXIA starts samp...harlan4096 — 08:17
QOwnNotes
26.2.15  Fix Qt5 ...Kool — 07:30

[-]
Birthdays
Today's Birthdays
avatar (50)daadAmomo
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (51)Claudestync
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>