Microsoft and other security researchers reported multiple campaigns in which attackers abused trusted cloud email environments to deliver phishing, spam, and business email compromise. In one Microsoft 365 intrusion set, attackers used credential stuffing against privileged accounts that lacked MFA, then registered malicious single-tenant OAuth applications with Exchange.ManageAsApp and elevated roles to persist in victim tenants. They modified Exchange Online inbound connectors and mail flow rules to relay scam email from legitimate organizational domains, promoting deceptive sweepstakes offers that harvested payment details for recurring subscriptions. Separately, Spamhaus identified more than 450 compromised Google Workspace education domains being used to send phishing and scam messages from real mailboxes, extending the same account-takeover model beyond Microsoft environments.
Related reporting showed the same ecosystem of email abuse also supporting credential theft and financial fraud. Microsoft documented AiTM phishing operations using Evilginx2-style infrastructure to steal Office 365 passwords and session cookies, bypass MFA through cookie replay, and then access Outlook mailboxes, create inbox rules, and conduct payment fraud. Other campaigns used voicemail-themed HTML attachments, open redirect chains, Google reCAPTCHA gates, and spoofed Microsoft notifications such as Power BI alerts to harvest credentials at scale. Across the incidents, defenders were urged to enforce phishing-resistant MFA, disable legacy access, review forwarding rules and connected apps, monitor anomalous sign-ins and suspicious mailbox or transport-rule changes, and rapidly investigate compromised accounts being used as trusted sender infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
15 events from the most recent confirmed update back to the earliest known activity.
Zscaler said it had monitored an active voicemail-themed phishing campaign since May 2022 targeting users at US-based organizations. The campaign used malicious HTML attachments, personalized redirector URLs, Google reCAPTCHA, and Office 365-themed credential harvesting pages.
Microsoft said a large-scale adversary-in-the-middle phishing campaign had attempted to target more than 10,000 organizations since September 2021. The operation used Evilginx2-style infrastructure to steal passwords and authenticated session cookies and then conduct follow-on business email compromise.
Microsoft observed a fresh spam run in August that used an updated Microsoft-spoofing lure and redirect URL while reusing the same phishing infrastructure and redirection chain from the broader open-redirect campaign.
On July 6, 2020, Zscaler observed connection attempts to secure.ciscovoicemail.cf, a phishing site spoofing Cisco Unity Connection voicemail. The site redirected victims to credential-harvesting pages targeting Office 365, Mimecast, Outlook Web Access, Gmail, Yahoo, and generic login brands.
Zscaler observed an increase in voicemail-themed social engineering attacks in July 2020 targeting end users in large enterprises. The campaign used HTML attachments, JavaScript redirects, reCAPTCHA, and fake login pages to steal credentials.
Zscaler identified multiple phishing domains registered between June and mid-July 2020 for a voicemail-themed credential theft campaign. Many used .xyz domains and recipient-specific URL parameters, with redirects to office.com when parameters were absent.
Zscaler reported that the first sample of a voicemail-themed HTML attachment used in a credential-phishing campaign was observed in the wild on April 21, 2020. The attachment redirected users to phishing sites spoofing services such as Office 365 and other webmail brands.
Spamhaus reported that attackers were abusing compromised Google Workspace accounts to send phishing and scam emails from legitimate organizational domains. It identified more than 450 compromised education domains using Google Workspace and said the abuse extended beyond the education sector.
Cofense reported a phishing campaign impersonating Microsoft Power BI notifications with a 'Weekly Sales Report' lure. Victims were sent to a spoofed Microsoft login page on non-Microsoft infrastructure, and after credential submission the campaign displayed a fake account-verification error.
Microsoft said it took down the malicious application network used in the cloud-tenant spam campaign and notified affected customers with remediation guidance. The company also noted that Outlook.com moved spam from the campaign to junk folders before users could interact with it.
In the Microsoft 365 tenant compromise campaign, attackers used privileged OAuth applications to create inbound connectors and transport rules in Exchange Online, then sent spam that appeared to originate from victim domains. The messages promoted deceptive sweepstakes offers intended to trick recipients into entering credit card details for recurring paid subscriptions.
Microsoft investigated a campaign in which attackers used credential stuffing against privileged Microsoft 365 and Azure AD accounts that lacked MFA. After gaining access, they registered malicious single-tenant OAuth applications and granted them Exchange.ManageAsApp and high-level administrative roles for persistence.
Microsoft tracked a widespread credential phishing campaign that abused open redirector links on legitimate domains and used CAPTCHA-gated fake sign-in pages to steal credentials. Microsoft observed at least 350 unique phishing domains and published indicators and hunting guidance for the operation.
Microsoft, MSTIC, and multiple cloud security teams coordinated to report abuse tied to the BEC operation, and cloud security teams suspended offending attacker accounts. This action resulted in the takedown of the cross-cloud attacker infrastructure.
Microsoft researchers uncovered a large-scale business email compromise operation that used phishing to steal mailbox credentials and then created malicious forwarding and deletion rules to exfiltrate finance-related emails. The operation affected hundreds of compromised mailboxes across multiple organizations and used cloud-hosted infrastructure and automation tools such as EmailRuler.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecofense.com
Open sourcezscaler.com
Open sourcezscaler.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourcedocs.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.