Contact to us

Peridot Network

NEWS HUB

Kaspersky detected over 31,000 scam emails abusing Microsoft authentication system in seven weeks

Islamabad : Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From August 1 to September 18, more than 31,000 emails with such links were blocked by Kaspersky solutions.

Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft’s authentication mechanism. Now Kaspersky experts explain how cybercriminals are exploiting the same technology, using another bait for the phishing: attackers sent victims emails disguised as an official Microsoft communication, urging them to follow the link to keep their credentials for the service updated or to sign electronic documents.

For making a redirect, attackers first create a Microsoft account and log into the Microsoft Entra admin center. In the application registration section the fraudsters create a new application. When registering the application, the service allows specifying a redirect URI (Uniform Resource Identifier) – the address to which the Microsoft Entra authentication server sends the user after successful authorization. In this field, the attackers add a link to their malicious site. Then the fraudsters send messages with Microsoft redirect links, containing Application ID of the registered app and the specified redirect URI.
Thus, by clicking on the link users get to a resource aimed at stealing personal data or downloading malicious software.

Using the Microsoft Entra admin center, attackers also discovered a way to embed their malicious content into the service’s legitimate notifications. Most likely, they have to purchase the cheapest license or start a trial period.
Spammers put a fake message in the name field on the Overview page, then create bogus users in the Users section with made up email addresses, display names and passwords. Then attackers log into the Microsoft My Account portal with the new credentials of the created bogus user and enter the victim’s real email address as a backup mailbox (used for password reset messages).

As a result, the victim receives an unsolicited verification code and scammers’ fraudulent message appears in the email’s subject and signature.

“It’s not the first time we have observed that fraudulent links and messages are not sent ostensibly on behalf of the real company, but are sent through official services. This adds a dangerous layer of credibility, making the scam harder to spot. Traditional phishing cues don’t apply well, so detecting it on your own is difficult. We strongly advise users to deploy a security solution with a robust anti phishing component, ensuring automatic protection even against the most sophisticated phishing attacks,” comments Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky.

To establish a comprehensive defense against such threats, organizations should consider using robust email security solutions. For corporate users, Kaspersky Security for Mail Server delivers robust protection against a wide range of advanced mail-borne threats.

For individual users, Kaspersky Premium offers anti-phishing features designed to help avoid phishing attacks and improve overall cybersecurity.

Leave a Reply

Your email address will not be published. Required fields are marked *