Microsoft 365 Phishing Scam
Summary
Early reports about the operation saw the fraudsters posing as the U.S. Department of Labor with the lure messages claiming to deliver PDFs with instructions about the bidding process for relevant projects. Researchers report that the newer phishing emails now have more consistent formatting, display the logos of the legitimate departments more prominently, and have switched to including a link to the PDF instead of carrying the file itself as an attachment. The metadata of the delivered PDFs also has been improved to now match the spoofed department whereas previously all PDF documents had the same signee - edward ambakederemo. The goal of the fraudsters is to obtain users Microsoft Office 356 account credentials and several improvements have been observed on the phishing portals themselves. The operators of the phishing attack also have included a CAPTCHA check as a way to endure that only real users fall for the trap.