Tag: Microsoft 365 phishing

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks
News

Axios Abuse and Salty 2FA Kits Fuel Advanced Microsoft 365 Phishing Attacks

According to new research from ReliaQuest, threat actors are exploiting Microsoft's Direct Send functionality in combination with HTTP client tools like Axios to create a "highly efficient attack pipeline" in recent phishing attempts. According to a study published with The Hacker News, Axios user agent activity increased 241% between June and August 2025, outpacing the 85% growth of all other flagged user agents combined. Axios was responsible for 24.44% of all activity among the 32 flagged user agents that were seen during this period. Account takeover (ATO) attacks on Microsoft 365 systems were previously reported by Proofpoint in January 2025, which detailed campaigns that used HTTP clients to send HTTP requests and get HTTP answers from web servers. ReliaQuest told The Hacke...
EvilProxy uses indeed.com open redirect for Microsoft 365 phishing
News

EvilProxy uses indeed.com open redirect for Microsoft 365 phishing

Key executives in U.S.-based companies are the focus of a freshly discovered phishing effort that takes advantage of open redirects from the Indeed jobs website. The threat actor is utilizing the phishing service EvilProxy, which can gather session cookies and be utilized to get around multi-factor authentication (MFA) systems. Executives and high-ranking personnel from a variety of industries, including electronic manufacturing, banking and finance, real estate, insurance, and property management, are the targets of this phishing attempt, according to researchers at Menlo Security. Redirects are legitimate URLs that take visitors automatically to another online location read more EvilProxy uses indeed.com open redirect for Microsoft 365 phishing.