Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[.

❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[.

Scheduled Pinned Locked Moved Uncategorized
threatintelspaminfoseccybersecurity
5 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • spamhaus@infosec.exchangeS This user is from outside of this forum
    spamhaus@infosec.exchangeS This user is from outside of this forum
    spamhaus@infosec.exchange
    wrote last edited by
    #1

    ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.

    The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:

    ✉️ Here's an example:
    "Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."

    At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.

    This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
    https://mastodon.social/@zackwhittaker/116562360000833298

    ....although the activity we’re seeing appears to stretch back several months.

    Takeaway: automated notification systems should not allow this level of customization.

    Microsoft has been informed of this abusive activity.

    #ThreatIntel #Spam #InfoSec #CyberSecurity

    Link Preview Image
    gossithedog@cyberplace.socialG infosecfemthing@infosec.exchangeI 2 Replies Last reply
    1
    0
    • spamhaus@infosec.exchangeS spamhaus@infosec.exchange

      ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.

      The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:

      ✉️ Here's an example:
      "Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."

      At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.

      This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
      https://mastodon.social/@zackwhittaker/116562360000833298

      ....although the activity we’re seeing appears to stretch back several months.

      Takeaway: automated notification systems should not allow this level of customization.

      Microsoft has been informed of this abusive activity.

      #ThreatIntel #Spam #InfoSec #CyberSecurity

      Link Preview Image
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.socialG This user is from outside of this forum
      gossithedog@cyberplace.social
      wrote last edited by
      #2

      @spamhaus @zackwhittaker yep that one has been going on for months. It's this: https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing

      Entra ID tenant branding. I've been trying to get Microsoft to do something about it for most of the year.

      spamhaus@infosec.exchangeS 1 Reply Last reply
      0
      • spamhaus@infosec.exchangeS spamhaus@infosec.exchange

        ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution.

        The header and message body appear completely legitimate - the abuse is happening through injection into the Subject:

        ✉️ Here's an example:
        "Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code."

        At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name.

        This also appears to line up with what @zackwhittaker TechCrunch Security Editor identified last week:
        https://mastodon.social/@zackwhittaker/116562360000833298

        ....although the activity we’re seeing appears to stretch back several months.

        Takeaway: automated notification systems should not allow this level of customization.

        Microsoft has been informed of this abusive activity.

        #ThreatIntel #Spam #InfoSec #CyberSecurity

        Link Preview Image
        infosecfemthing@infosec.exchangeI This user is from outside of this forum
        infosecfemthing@infosec.exchangeI This user is from outside of this forum
        infosecfemthing@infosec.exchange
        wrote last edited by
        #3

        @spamhaus yeah this has been going on for a while, and Microsoft has done seemingly nothing to combat the issue.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          @spamhaus @zackwhittaker yep that one has been going on for months. It's this: https://abnormal.ai/blog/system-notification-abuse-microsoft-phishing

          Entra ID tenant branding. I've been trying to get Microsoft to do something about it for most of the year.

          spamhaus@infosec.exchangeS This user is from outside of this forum
          spamhaus@infosec.exchangeS This user is from outside of this forum
          spamhaus@infosec.exchange
          wrote last edited by
          #4

          @GossiTheDog @zackwhittaker thanks for sharing 🙏

          interpipes@thx.ggI 1 Reply Last reply
          0
          • spamhaus@infosec.exchangeS spamhaus@infosec.exchange

            @GossiTheDog @zackwhittaker thanks for sharing 🙏

            interpipes@thx.ggI This user is from outside of this forum
            interpipes@thx.ggI This user is from outside of this forum
            interpipes@thx.gg
            wrote last edited by
            #5

            @spamhaus @GossiTheDog @zackwhittaker same as calendly emails, and as sharepoint and gmail shared document links before them, etc etc etc repeat ad nauseum.

            Here's a calendly one from today that M365 mail filtering decided needed to be delivered to my inbox.

            Had to zoom out so that you can actually see the calendly footer, because calendly /also/ lets people insert a load of whitespace to try to hide their footer "below the fold"

            Link Preview Image
            1 Reply Last reply
            0
            • R relay@relay.mycrowd.ca shared this topic
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • World
            • Users
            • Groups