Kaspersky experts have identified a scam email campaign. Attackers send emails that contain legitimate Microsoft service links to redirect users to fraudulent sites or to download malware. From August 1 to September 18, more than 31,000 emails with such links were blocked by Kaspersky solutions.
Earlier this year Kaspersky reported detecting a phishing campaign where attackers abused Microsoft’s authentication mechanism. Now Kaspersky experts explain how cybercriminals are exploiting the same technology, using another bait for the phishing: attackers sent victims emails disguised as an official Microsoft communication, urging them to follow the link to keep their credentials for the service updated or to sign electronic documents.
For making a redirect, attackers first create a Microsoft account and log into the Microsoft Entra admin center. In the application‑registration section the fraudsters create a new application. When registering the application, the service allows specifying a redirect URI (Uniform Resource Identifier) – the address to which the Microsoft Entra authentication server sends the user after successful authorization. In this field, the attackers add a link to their malicious site. Then the fraudsters send messages with Microsoft redirect links, containing Application ID of the registered app and the specified redirect URI.
Thus, by clicking on the link users get to a resource aimed at stealing personal data or downloading malicious software.
Using the Microsoft Entra admin center, attackers also discovered a way to embed their malicious content into the service’s legitimate notifications. Most likely, they have to purchase the cheapest license or start a trial period.
Spammers put a fake message in the name field on the Overview page, then create bogus users in the Users section with made‑up email addresses, display names and passwords. Then attackers log into the Microsoft My Account portal with the new credentials of the created bogus user and enter the victim’s real email address as a backup mailbox (used for password‑reset messages).
As a result, the victim receives an unsolicited verification code and scammers’ fraudulent message appears in the email’s subject and signature.
“It’s not the first time we have observed that fraudulent links and messages are not sent ostensibly on behalf of the real company, but are sent through official services. This adds a dangerous layer of credibility, making the scam harder to spot. Traditional phishing cues don’t apply well, so detecting it on your own is difficult. We strongly advise users to deploy a security solution with a robust anti‑phishing component, ensuring automatic protection even against the most sophisticated phishing attacks,” comments Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky.
To establish a comprehensive defense against such threats, organizations should consider using robust email security solutions. For corporate users, Kaspersky Security for Mail Server delivers robust protection against a wide range of advanced mail-borne threats. Powered by machine learning algorithms, its multi-layered defense mechanisms offer businesses complete peace of mind in the face of evolving cyber risks.
For individual users, Kaspersky Premium offers anti-phishing features designed to help avoid phishing attacks and improve overall cybersecurity. To ensure advanced protection against increasingly complex cyber threats, Kaspersky actively amplifies its consumer solutions with AI-powered scam protection – a unified suite of technologies that combines machine learning-based anti-phishing algorithms, real-time behavior monitoring, accompanied by Data Leak and Identity Theft checkers.
About Kaspersky
Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.
Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.
Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.
Tracy
