Website Security & Threat Management
Phishpoint back in full swing: an infamous Microsoft SharePoint spoof resumes with new tactics

Phishpoint back in full swing: an infamous Microsoft SharePoint spoof resumes with new tactics

12/11/2020 · Elaine Dzuba

What this post added

This post details a new wave of Microsoft SharePoint phishing campaigns that leverage COVID-19 restrictions to steal victim login information. The campaign utilizes cloud computing services for hosting credential harvesters and abuses reputable email providers like SendGrid to bypass traditional email security gateways. The spoofed login pages are hosted on platforms like AWS, Google App Engine, and Firebase, and are designed to closely mimic legitimate Microsoft login pages. The analysis includes details on the JavaScript used to extract victim emails from URLs and the methods used to exfiltrate credentials. Indicators of compromise for malicious links and sites are provided.

Read the original post ↗