Happy New Year 2026 to all our members and visitors! Our Forum is Now Back Online After Some Critical Upgrade- We Apologize for the inaccessibility Period! Thank You all. CORONAVIRUS safety tips from Admin! 1. Watch your hands with running water 2. Dont cough in your hands 3. Keep distance from people 4. Stay indoor if neccessary!! Stay safe !!! Dear Members,Do you know that naijacrux is fully programmed to serve you better, Do you know that you can share your favorite post on naijacrux with friends on twitter,facebook, googleplus,myspace and many more! To share post on naijacrux with friends and family on twitter, facebook,googleplus,myspace,and many more, scroll to the down page of the post, Click on the Social Icon You Want To Share On To Share.


Author Topic: This Cyber Attack Targets Microsoft 365 Accounts  (Read 233 times)

0 Members and 1 Guest are viewing this topic.

Offline Nairaland

  • Global Moderator
  • Sr. Member
  • *****
  • Posts: 405
  • Karma: +0/-0
This Cyber Attack Targets Microsoft 365 Accounts
« on: April 26, 2025, 03:58:38 PM »
Advertisement
This Cyber Attack Targets Microsoft 365 Accounts

A new cyberattack is targeting Microsoft 365 users through Signal and WhatsApp messages, with hackers impersonating government officials in order to gain access to accounts.

According to reporting from Bleeping Computer, bad actors—who are believed to be Russians pretending to be European political officials or diplomats—are contacting employees of organizations working on issues related to Ukraine and human rights. The end goal is to trick targets into clicking an OAuth phishing link leading them to authenticate their Microsoft 365 credentials.

This scam, first discovered by cybersecurity firm Volexity, has focused specifically on organizations related to Ukraine, but a similar approach could be used more widely to steal user data or take over devices.

How the Microsoft 365 OAuth attack works

This attack typically begins with targets receiving a message via Signal or WhatsApp from a user posing as a political official or diplomat with an invitation to a video call or conference to discuss issues related to Ukraine.

According to Volexity, attackers may claim to be from the Mission of Ukraine to the European Union, the Permanent Delegation of the Republic of Bulgaria to NATO, or the Permanent Representation of Romania to the European Union. In one variation, the campaign starts with an email sent from a hacked Ukrainian government account followed by communication via Signal and WhatsApp.

Once a thread is established, bad actors send victims PDF instructions along with an OAuth phishing URL. When clicked, the user is prompted to log into Microsoft and third-party apps that utilize Microsoft 365 OAuth and redirected to a landing page with an authentication code, which they are told to share in order to enter the meeting. This code, which is valid for 60 days, gives attackers access to email and other Microsoft 365 resources, even if victims change their passwords.

How to spot the Microsoft 365 OAuth attack

This attack is one of several recent threats abusing OAuth authentication, which can make it harder to identify as suspect, at least from a technical point of view. Volexity recommends setting up conditional access policies on Microsoft 365 accounts to approved devices only, as well as enabling login alerts.

Users should also be wary of social engineering tactics that play on human psychology to successfully carry out phishing and other types of cyber attacks. Examples include messages that are unusual or out of character—especially for a sender you know or trust—communication that prompts an emotional response (like fear or curiosity), and requests that are urgent or offers that are too good to be true.

A social engineering explainer from CSO advises a "zero-trust mindset" as well as watching out for common signs like grammar and spelling mistakes and instructions to click links or open attachments. Screenshots of the Signal and WhatsApp messages shared by Volexity show small errors that give them away as potentially fraudulent.


Source: This Cyber Attack Targets Microsoft 365 Accounts


 

 

Bangladesh rejects IS claims of responsibility for cafe attack that killed 124

Started by internet police

Replies: 0
Views: 1971
Last post July 04, 2016, 02:46:37 AM
by internet police
Hausa Youths Attack Igbo Man In Lagos For Blasphemy

Started by jchima14

Replies: 0
Views: 1778
Last post September 06, 2016, 07:56:26 PM
by jchima14
The ‘Pixnapping’ Attack Can Steal Your 2FA Codes

Started by Nairaland

Replies: 0
Views: 105
Last post October 23, 2025, 09:31:21 AM
by Nairaland
Microsoft Is Now Testing a 'Built-In' Network Speed Test Tool in Windows 11

Started by Nairaland

Replies: 0
Views: 71
Last post February 28, 2026, 09:32:45 AM
by Nairaland
Microsoft's Latest 'Patch Tuesday' Fixes 134 Security Vulnerabilities

Started by Nairaland

Replies: 0
Views: 1197
Last post April 13, 2025, 07:32:24 AM
by Nairaland