{"id":5697,"date":"2026-10-08T14:42:03","date_gmt":"2026-10-08T09:42:03","guid":{"rendered":"https:\/\/pcn58.com.pk\/?p=5697"},"modified":"2026-10-08T14:42:04","modified_gmt":"2026-10-08T09:42:04","slug":"kaspersky-detected-over-31000-scam-emails-abusing-microsoft-authentication-system-in-seven-weeks","status":"publish","type":"post","link":"https:\/\/pcn58.com.pk\/index.php\/2026\/10\/08\/kaspersky-detected-over-31000-scam-emails-abusing-microsoft-authentication-system-in-seven-weeks\/","title":{"rendered":"Kaspersky detected over 31,000 scam emails abusing Microsoft authentication\u202fsystem in seven weeks"},"content":{"rendered":"\n<p>Islamabad : Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From\u202fAugust\u202f1 to\u202fSeptember\u202f18, more than\u202f31,000\u202femails with such links were blocked by Kaspersky solutions.<\/p>\n\n\n\n<p>Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft\u2019s authentication mechanism. Now Kaspersky experts explain how cybercriminals are exploiting the same technology, using another bait for the phishing: attackers sent victims emails disguised as an official Microsoft communication, urging them to follow the link to keep their credentials for the service updated or to sign electronic documents.<\/p>\n\n\n\n<p>For making a redirect, attackers first create a Microsoft account and log into the Microsoft Entra admin center. In the application registration section the fraudsters create a new application. When registering the application, the service allows specifying a redirect\u202fURI (Uniform Resource Identifier) \u2013 the address to which the Microsoft Entra authentication server sends the user after successful authorization. In this field, the attackers add a link to their malicious site. Then the fraudsters send messages with Microsoft redirect links, containing Application ID of the registered app and the specified redirect URI.<br>Thus, by clicking on the link users get to a resource aimed at stealing personal data or downloading malicious software.<\/p>\n\n\n\n<p>Using the Microsoft Entra admin center, attackers also discovered a way to embed their malicious content into the service\u2019s legitimate notifications. Most likely, they have to purchase the cheapest license or start a trial period.<br>Spammers put a fake message in the name field on the Overview page, then create bogus users in the Users section with made up email addresses, display names and passwords. Then attackers log into the Microsoft\u202fMy\u202fAccount portal with the new credentials of the created bogus user and enter the victim\u2019s real email address as a backup mailbox (used for password reset messages).<\/p>\n\n\n\n<p>As a result, the victim receives an unsolicited verification code and scammers\u2019 fraudulent message appears in the email\u2019s subject and signature.<\/p>\n\n\n\n<p>\u201cIt\u2019s not the first time we have observed that fraudulent links and messages are not sent ostensibly on behalf of the real company, but are sent through official services. This adds a dangerous layer of credibility, making the scam harder to spot. Traditional phishing cues don\u2019t apply well, so detecting it on your own is difficult. We strongly advise users to deploy a security solution with a robust anti phishing component, ensuring automatic protection even against the most sophisticated phishing attacks,\u201d comments Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky.<\/p>\n\n\n\n<p>To establish a comprehensive defense against such threats, organizations should consider using robust email security solutions. For corporate users, Kaspersky Security for Mail Server delivers robust protection against a wide range of advanced mail-borne threats.<\/p>\n\n\n\n<p>For individual users, Kaspersky Premium offers anti-phishing features designed to help avoid phishing attacks and improve overall cybersecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Islamabad : Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From\u202fAugust\u202f1 to\u202fSeptember\u202f18, more than\u202f31,000\u202femails with such links were blocked by Kaspersky solutions. Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft\u2019s authentication [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":5698,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[12],"tags":[132],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5697"}],"collection":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/comments?post=5697"}],"version-history":[{"count":1,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5697\/revisions"}],"predecessor-version":[{"id":5699,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/posts\/5697\/revisions\/5699"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/media\/5698"}],"wp:attachment":[{"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/media?parent=5697"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/categories?post=5697"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pcn58.com.pk\/index.php\/wp-json\/wp\/v2\/tags?post=5697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}