Microsoft 365 Phishing Scam

General News

Summary

Early reports about the operation saw the fraudsters posing as the U.S. Department of Labor with the lure messages claiming to deliver PDFs with instructions about the bidding process for relevant projects. Researchers report that the newer phishing emails now have more consistent formatting, display the logos of the legitimate departments more prominently, and have switched to including a link to the PDF instead of carrying the file itself as an attachment. The metadata of the delivered PDFs also has been improved to now match the spoofed department whereas previously all PDF documents had the same signee - edward ambakederemo. The goal of the fraudsters is to obtain users Microsoft Office 356 account credentials and several improvements have been observed on the phishing portals themselves. The operators of the phishing attack also have included a CAPTCHA check as a way to endure that only real users fall for the trap.

Classifications

industries
Entertainment
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M
Microsoft
$1B+