Tag: microsoft 365

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
News

HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050

Using a compromised Microsoft 365 calendar as its command channel, a recently found espionage implant has been smuggling out stolen files as attachments on calendar events dating back to 2050 and planting operator instructions. According to Group-IB, which gave the malware the name HollowGraph, the method transfers tasking and stolen data through authentic Microsoft Graph API traffic, making the activity appear like regular Microsoft 365 chatter and preventing network controls keyed to attacker-owned destinations from raising any red flags. The implant is a.NET DLL that only accepts the commands "get" and "send," and it never sends payloads to a server owned by the attacker. Rather, it handles the calendar in the hijacked email as a two-way dead drop. In order to pull tasking, it...
Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag
News

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

The check that restricts account-token sharing to trustworthy Microsoft applications was deactivated in production builds of multiple Microsoft 365 Android apps due to a development flag that was left enabled. In order to read emails, open files, view the calendar, and send messages as that user, any other app on the same phone could request and obtain the token of the logged-in user. No login screen, no password, and no need for permission. If you use Microsoft 365 apps on Android, please update them as Microsoft has corrected the issue. Word, PowerPoint, Excel, Microsoft 365 Copilot, Microsoft Loop, and OneNote were among the six programs with billions of downloads that were affected by the flaw, which Enclave refers to as FlagLeft. Enclave interprets this as a slip rather than...
ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens
News

ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens

ToddyCat, a threat actor, has been seen using new techniques, such as a bespoke tool called TCSectorCopy, to gain access to target firms' corporate email data. According to a technical breakdown by Kaspersky, this attack enables them to collect tokens for the OAuth 2.0 authorization protocol using the user's browser, which may be utilized outside the perimeter of the compromised infrastructure to access business mail. ToddyCat, which has been active since 2020, has a history of using tools like Samurai and TomBerBil to target different enterprises in Europe and Asia in order to maintain access and steal passwords and cookies from web browsers like Google Chrome and Microsoft Edge. The hacking organization was identified earlier in April for using a security vulnerability in ESET ...
New VoidProxy phishing service targets Microsoft 365, Google accounts
News

New VoidProxy phishing service targets Microsoft 365, Google accounts

VoidProxy is a recently identified phishing-as-a-service (PhaaS) platform that targets Google and Microsoft 365 accounts, including those secured by third-party single sign-on (SSO) providers like Okta. Real-time credentials, multi-factor authentication (MFA) codes, and session cookies are stolen by the platform using adversary-in-the-middle (AitM) techniques. Researchers from Okta Threat Intelligence found VoidProxy, which they characterize as clever, elusive, and scalable. The attack starts with emails that contain shortened URLs that, after several redirections, take recipients to phishing websites. These emails come from hijacked accounts at email service providers such as Constant Contact, Active Campaign, and NotifyVisitors. The malicious websites are housed on cheap, dispo...
Microsoft adds malicious link warnings to Teams private chats
News

Microsoft adds malicious link warnings to Teams private chats

When users send or receive a private message that contains links that have been flagged as harmful, Microsoft Teams will automatically notify them. For all Microsoft Defender for Office 365 (MDO) and Microsoft Teams enterprise customers, Microsoft will implement these new alerts for communications that contain URLs that have been identified as spam, phishing, or malware. According to a new Microsoft 365 roadmap article, the new link protection function will be made available to the entire public in November 2025 after starting with a public preview for desktop, Android, web, and iOS users in September 2025. We're introducing message warnings in Microsoft Teams to assist customers stay safe from dangerous content, the company said in an incident alert posted in the Microsoft 365 m...
Microsoft Defender for Office 365 now blocks email bombing attacks
News

Microsoft Defender for Office 365 now blocks email bombing attacks

According to Microsoft, email bombing threats will now be automatically detected and blocked by its Defender for Office 365 cloud-based email protection package. Defender for Office 365 (formerly known as Office 365 Advanced Threat Protection or Office 365 ATP) defends businesses dealing with sophisticated threat actors and high-risk industries against harmful threats from links, emails, and collaboration platforms. In a Microsoft 365 message center update, Redmond writes, We're introducing a new detection capability in Microsoft Defender for Office 365 to help protect your organization from a growing threat known as email bombing. This type of exploitation overwhelms systems or obscures essential messages by flooding mailboxes with large amounts of email. Security teams will be ...
Botnet targets Basic Auth in Microsoft 365 password spray attacks
News

Botnet targets Basic Auth in Microsoft 365 password spray attacks

Password-spray assaults against Microsoft 365 (M365) accounts globally are being carried out by a vast botnet of more than 130,000 infected machines, which targets basic authentication in order to circumvent multi-factor authentication. According to a SecurityScorecard assessment, the attackers are targeting the accounts on a broad scale by using credentials that were acquired by infostealer malware. To get beyond Multi-Factor Authentication (MFA) safeguards and obtain unauthorized access without setting off security alerts, the assaults rely on non-interactive sign-ins using Basic Authentication (Basic Auth). Businesses that only use interactive sign-in monitoring are unaware of these threats read more about Botnet targets Basic Auth in Microsoft 365 password spray attacks. G...
Microsoft 365 admins warned of new Google anti-spam rules
News

Microsoft 365 admins warned of new Google anti-spam rules

This week, Microsoft issued a warning to Microsoft 365 email senders advising them to authenticate outbound messages. This action was motivated by Google's recent announcement of stronger anti-spam guidelines for bulk senders. By setting up email authentication for your domain, you can ensure that your messages are less likely to be rejected or marked as spam by email providers like Gmail, Yahoo, AOL, and Outlook.com," the Microsoft Defender for Office 365 team noted. This is especially important when sending bulk email (large volume email), as it helps maintain the deliverability and reputation of your email campaigns read more Microsoft 365 admins warned of new Google anti spam rules. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our...