Tuesday, 02 January 2024 12:17 GMT

M365 Phishing Campaign Clusters Attacks In US Workday Arabian Post


(MENAFN- The Arabian Post) clearfix">Cybercriminals abusing Microsoft 365's Direct Send feature concentrated malicious email activity around US Eastern business hours, according to a new analysis of a large phishing campaign tracked during July and August.

KnowBe4 Threat Lab said it identified tens of thousands of confirmed phishing messages sent through Direct Send, a legitimate Exchange Online delivery method intended for devices and applications that need to send mail without a dedicated Microsoft 365 mailbox. The researchers said the timing showed a pronounced weekday pattern, with activity strongest early in the working week and volumes rising through the morning before reaching their highest point around 2pm Eastern Time.

The campaign matters because Direct Send can allow an attacker to make a message appear to come from an organisation's own domain without first compromising an employee account. By connecting to the target organisation's Exchange Online MX endpoint, a sender can submit mail that is treated as anonymous internet traffic while using an address from the organisation's accepted domain.

MENAFN13092026000152002308ID1111658692



The Arabian Post

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story