TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

SecurityWeek

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations

Eduard Kovacs · 1 day ago · Read original ↗

ATT&CK techniques detected

8 predictions
T1566.002Spearphishing Link
89%
"microsoft warns of sophisticated phishing campaign targeting us organizations microsoft has warned organizations in the united states about a sophisticated phishing campaign that uses a “ code of conduct review ” theme to lure victims to a malicious website. the tech giant observ…"
T1566.002Spearphishing Link
88%
"that are likely attacker - controlled, ” microsoft explained. the recipient is instructed to open a personalized attachment to review case materials. the attachments are pdf documents titled ‘ awareness case log file ’ or ‘ disciplinary action ’ that direct the user to click the …"
T1556.006Multi-Factor Authentication
76%
", bypassing non - phishing - resistant multifactor authentication ( mfa ), ” microsoft noted. enterprises at risk of being targeted in this and similar phishing campaigns have been provided with recommendations for mitigating attacks, as well as threat - hunting queries and indic…"
T1621Multi-Factor Authentication Request Generation
56%
", bypassing non - phishing - resistant multifactor authentication ( mfa ), ” microsoft noted. enterprises at risk of being targeted in this and similar phishing campaigns have been provided with recommendations for mitigating attacks, as well as threat - hunting queries and indic…"
T1566.001Spearphishing Attachment
53%
"microsoft warns of sophisticated phishing campaign targeting us organizations microsoft has warned organizations in the united states about a sophisticated phishing campaign that uses a “ code of conduct review ” theme to lure victims to a malicious website. the tech giant observ…"
T1598.002Spearphishing Attachment
45%
"microsoft warns of sophisticated phishing campaign targeting us organizations microsoft has warned organizations in the united states about a sophisticated phishing campaign that uses a “ code of conduct review ” theme to lure victims to a malicious website. the tech giant observ…"
T1111Multi-Factor Authentication Interception
40%
"that are likely attacker - controlled, ” microsoft explained. the recipient is instructed to open a personalized attachment to review case materials. the attachments are pdf documents titled ‘ awareness case log file ’ or ‘ disciplinary action ’ that direct the user to click the …"
T1566.002Spearphishing Link
34%
", bypassing non - phishing - resistant multifactor authentication ( mfa ), ” microsoft noted. enterprises at risk of being targeted in this and similar phishing campaigns have been provided with recommendations for mitigating attacks, as well as threat - hunting queries and indic…"

Summary

The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM.

The post Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations appeared first on SecurityWeek.