Beware this new spear-phishing campaign that mirrors official spoofs Microsoft Exchange emails

Hook on Keyboard
(Image credit: wk1003mike / Shutterstock)

A new spear-phishing campaign has been discovered that uses spoof Microsoft Exchange emails to target Office 365 users. The well-coordinated attack has a broad range of targets but appears to be predominantly focused on Office 365 users within several key industries, including healthcare, insurance, financial services, and manufacturing.

Security researchers at email security platform IRONSCALES discovered the attack after finding that almost 100 of its customers were being targeted. The attack employs a sophisticated domain spoofing technique that makes it difficult to determine whether the phishing email is genuine or not.

Attackers send a message claiming to be from “Microsoft Outlook,” asking users to retrieve an email that has been marked as phishing or spam communications – a relatively new Office 365 feature. The reclaimed message states that it is urgent that the user clicks on a contained link. The link then redirects them to a fake Office 365 login page, where their credentials are harvested by the attacker.

If in doubt, don't click

This particular spear-phishing campaign employs domain spoofing, which isn’t usually particularly successful – in fact, exact domain spoofs constitute less than 1% of email spoofing attacks that bypass email gateways. Normally, the domain-based message authentication, reporting & conformance (DMARC) protocol stops these fake messages in their tracks – but not in this case.

“Our research found that Microsoft servers are not currently enforcing the DMARC protocol, meaning these exact domain spoofing messages are not being rejected by gateway controls, such as Office 365 Exchange Online Protection and Advanced Threat Protection,” Lomy Ovadia, the vice president of R&D at IRONSCALES, explained. “This is especially perplexing when considering Microsoft frequently ranks as a top-five most spoofed brand year after year.”

For any email provider, a successful phishing campaign provides an opportunity to reflect on how its security protocols could be improved. For Microsoft, the fact that attackers are able to use its own domain and, even, a newly launched Office 365 feature against them is particularly embarrassing.

TOPICS
Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
Klipsch Klipschorn AK7 in a room with lots of dark wood furniture and a bare brick wall
Klipsch just updated two of its most iconic stereo speaker designs, keeping these beautiful retro icons on your most-wanted list
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?