HomeCyber BalkansMicrosoft Issues Warning About Cloud Storage and Financial Fraud Campaign

Microsoft Issues Warning About Cloud Storage and Financial Fraud Campaign

Published on

spot_img

Microsoft Alerts Customers on New Social Engineering Threats: A Closer Look at Evolving Cyber Attacks

In a significant warning to its users, Microsoft has raised concerns regarding two highly sophisticated social engineering campaigns designed to target corporate accounts and financial systems. These alerts come as organizations increasingly rely on digital platforms for operations, making them more susceptible to various cyber threats.

The first of these campaigns employs tactics such as phone calls and messaging, where attackers impersonate Microsoft representatives. They inform victims about supposed necessary updates to passkeys, multi-factor authentication, or single sign-on configurations. These communications aim to deceive individuals into visiting counterfeit login pages specifically crafted to harvest credentials and session tokens of unsuspecting users.

The second campaign is more discreet yet equally alarming, involving email impersonations of executives to initiate fraudulent Automated Clearing House (ACH) payments. This tactic involves communications that appear legitimate, requesting payments nearing $50,000. The sophistication of this email campaign indicates that attackers likely leverage generative AI to fabricate convincing email threads that mimic genuine corporate dialogues, thereby increasing the likelihood of successful fraud.

The credential theft campaign, which has been monitored since May 2026, follows two main pathways of attack. One proven method is the adversary-in-the-middle attack, where victims unknowingly log into fraudulent Microsoft portals hosted on domains such as passkeyhelpdesk[.]com or integratedsso[.]com. Many of these domains are designed with subdomains that closely resemble the legitimate companies they aim to exploit. Alternatively, attackers manipulate Microsoft’s genuine device code approval flow, commonly used for Internet of Things (IoT) devices. By convincing users to enter attacker-supplied codes into landing pages that look official, the perpetrators can bypass existing multi-factor authentication safeguards.

Once attackers gain access to a compromised account, they can register new multi-factor authentication devices, ensuring persistent access. Using Microsoft Graph, these attackers conduct reconnaissance to gather intelligence on users, group permissions, and accessible resources. They systematically and meticulously collect data from platforms like SharePoint Online, OneDrive for Business, and Exchange Online. Notably, the attackers have been identified as employing automated processes distinguished by the python-httpx user-agent, intentionally pacing their data theft to stay under thresholds—limiting their collection to fewer than 1,000 files per hour to avoid detection amidst regular business activities.

Microsoft has linked these initial access methods to prominent threat groups, identified as Storm-3121 and Storm-3032. These groups also have ties to various extortion syndicates, including ShinyHunters, Falcon, and Helix, indicating that the dissemination of these tactics is part of a more extensive network of cybercrime.

In a separate but equally concerning email fraud campaign, Microsoft disclosed that over one million messages were dispatched between August 3 and 5, with approximately 87.7% of the targets located in the United States. Victims in this scheme received emails that seemed to portray forwarded conversations between executives and legitimate vendors such as ServiceNow. These emails discussed and approved fraudulent invoices, which were rendered convincingly through untraceable email services and lookalike domains, including service-nowinc[.]com.

Upon investigation, Microsoft specialists detected various indicators typifying AI-generated content, such as extensive HTML remarks and an overuse of em dashes. Moreover, the fraudulent communications prominently displayed matching sender names, reply-to addresses, and signatures, alongside highly detailed forged invoices.

In light of these developing threats, Microsoft has issued a series of recommendations aimed at enhancing cyber defense measures. Companies should adopt phishing-resistant multi-factor authentication methods, such as FIDO2 passkeys or Windows Hello for Business. They are also advised to utilize Conditional Access to limit Exchange, SharePoint, and Graph access strictly to managed devices, and to block device code flows when unnecessary. Furthermore, organizations are encouraged to enable zero-hour auto purge in Office 365. This strategy retroactively quarantines suspicious emails, complementing automatic attack disruption configurations in Microsoft Defender XDR.

In the unfortunate event of a security compromise, administrators are advised to take decisive actions: revoking active sessions, refreshing tokens, resetting credentials, and eliminating any attacker-registered authentication methods or mailbox rules are critical steps in reclaiming control.

As cyber threats continue to evolve in sophistication and scale, organizations must remain vigilant and proactive in safeguarding their digital assets against these ever-present risks.

Source link

Latest articles

Admin Menu Editor Pro Plugin Backdoors Affect 1,500 WordPress Sites

Major Security Breach: Over 1,500 WordPress Sites Compromised by Malicious Plugin Updates In a shocking...

HBO Max Reddit Account Compromised for Malware Distribution

Cybercriminals Hijack HBO Max's Verified Reddit Account for Malware Distribution In a significant breach, cybercriminals...

Critical ScreenConnect Flaw Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a significant warning about...

Salesforce Global Outage Impacts Hundreds of Instances

Salesforce Experiences Major Global Outage, Disrupting Services During Key Conference On September 16, Salesforce, a...

More like this

Admin Menu Editor Pro Plugin Backdoors Affect 1,500 WordPress Sites

Major Security Breach: Over 1,500 WordPress Sites Compromised by Malicious Plugin Updates In a shocking...

HBO Max Reddit Account Compromised for Malware Distribution

Cybercriminals Hijack HBO Max's Verified Reddit Account for Malware Distribution In a significant breach, cybercriminals...

Critical ScreenConnect Flaw Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a significant warning about...