惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
Google DeepMind News
Google DeepMind News
Microsoft Security Blog
Microsoft Security Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
The GitHub Blog
The GitHub Blog
I
InfoQ
A
About on SuperTechFans
GbyAI
GbyAI
宝玉的分享
宝玉的分享
爱范儿
爱范儿
博客园 - 【当耐特】
博客园 - 司徒正美
博客园 - 聂微东
P
Proofpoint News Feed
WordPress大学
WordPress大学
云风的 BLOG
云风的 BLOG
Last Week in AI
Last Week in AI
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
Jina AI
Jina AI
aimingoo的专栏
aimingoo的专栏
J
Java Code Geeks
博客园 - 叶小钗

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Microsoft Flags Mass Phishing Campaign Using Fake Complia...
Beth Maundrill · 2026-05-05 · via www.infosecurity-magazine.com

A phishing campaign targeting more than 35,000 users across 13,000 organizations has been identified by the Microsoft Defender Research team.

The large-scale credential theft campaign used fake internal compliance or regulatory communications as lures for the campaign.

The lures in this campaign used polished, enterprise-style HTML templates with structured layouts and preemptive authenticity statements, making them appear more credible than typical phishing emails and increasing their plausibility as legitimate internal communications. 

The campaign ran between April 15 and 16, 2026, and primarily targeted US firms, but was identified in organizations across 26 countries total.

Urgent Compliance Phishing Lure

According to Microsoft’s findings, the messages contained concerning accusations and repeated time-bound action prompts. This gave the campaign a sense of urgency and pressure for victims to act.

For example, subject lines included “Internal case log issued under conduct policy” and the messages claimed that a “code of conduct review” had been initiated, and referenced organization-specific names embedded within the text.

The emails instructed recipients to “open the personalized attachment” to review case materials.

The attached PDF encouraged recipients to click the “Review Case Materials” link, this is what initiated the credential harvesting flow.

The attackers designed the message to appear legitimate by claiming it came from an authorized internal channel and that all links and attachments had been securely reviewed.

A green banner claiming the message had been encrypted using Paubox, a legitimate service associated with HIPAA-compliant communications, further reinforced credibility.

When the recipient clicked on the link within the PDF they were redirected to a landing page which displayed a Cloudflare CAPTCHA, presented as a mechanism to validate that the user was coming “from a valid session”. This was likely to deter automated analysis and sandboxes, according to Microsoft.

After passing the CAPTCHA, victims were redirected to another site claiming the documents were encrypted and required account authentication to proceed.

Microsoft observed an attack chain resembling device code phishing but confirmed only the adversary-in-the-middle (AiTM) component.

Victims were led through multiple staged pages with email entries, CAPTCHAs and reassuring status messages before being redirected, based on device type, to a final phishing site.

There, users were prompted to sign in with Microsoft under the guise of a compliance review, triggering an AiTM session hijack to steal authentication tokens and compromise accounts.

Protection Guidance From Microsoft

Microsoft recommended serval mitigations to reduce the impact of this threat, including, but not limited to:

  • Review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365 to ensure your organization has established essential defenses and knows how to monitor and respond to threat activity
  • Run realistic attack scenarios during awareness training so employees are prepared to spot such phishing attempts
  • Enable password-less authentication methods for accounts that support password-less. For accounts that still require passwords, use authenticator apps like Microsoft Authenticator for multifactor authentication (MFA)
  • Turn on Safe Links and Sade Attachments in Microsoft Defender for Office 365
  • Configure automatic attack disruption in Microsoft Defender XDR