惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
A
About on SuperTechFans
The Cloudflare Blog
G
Google Developers Blog
博客园_首页
Martin Fowler
Martin Fowler
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
D
Docker
C
Check Point Blog
T
Tailwind CSS Blog
博客园 - 司徒正美
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hugging Face - Blog
Hugging Face - Blog
Microsoft Security Blog
Microsoft Security Blog
V
V2EX
博客园 - 叶小钗
T
The Blog of Author Tim Ferriss
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
M
MIT News - Artificial intelligence
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 【当耐特】
GbyAI
GbyAI

The Hacker News

SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation 22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023 5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files ⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More Why Most AI Deployments Stall After the Demo Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories [Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data The Hacker News The Hacker News Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
Microsoft Details Phishing Campaign Targeting 35,000 User...
info@thehack · 2026-05-05 · via The Hacker News

Microsoft has disclosed details of a large-scale credential theft campaign that has leveraged a combination of code of conduct-themed lures and legitimate email services to direct users to attacker-controlled domains and steal authentication tokens.

The multi-stage campaign, observed between April 14 and 16, 2026, targeted more than 35,000 users across over 13,000 organizations in 26 countries, with 92% of the targets located in the U.S. The majority of phishing emails were directed against healthcare and life sciences (19%), financial services (18%), professional services (11%), and technology and software (11%) sectors.

"The lures in this campaign used polished, enterprise-style HTML templates with structured layouts and preemptive authenticity statements, making them appear more credible than typical phishing emails and increasing their plausibility as legitimate internal communications," the Microsoft Defender Security Research Team and Microsoft Threat Intelligence said.

"Because the messages contained accusations and repeated time-bound action prompts, the campaign created a sense of urgency and pressure to act."

The email messages used in the campaign employ lures related to code of conduct reviews, using display names like "Internal Regulatory COC," "Workforce Communications," and "Team Conduct Report." Subject lines associated with these emails include "Internal case log issued under conduct policy" and "Reminder: employer opened a non-compliance case log."

Cybersecurity

"At the top of each message, a notice stated that the message had been 'issued through an authorized internal channel' and that links and attachments had been 'reviewed and approved for secure access,' reinforcing the email's purported legitimacy," Microsoft explained.

It's assessed that the emails are sent from a legitimate email delivery service. The messages also come with a PDF attachment that purportedly gives additional information about the conduct review, luring victims to click on a link within the document to initiate the credential harvesting flow.

The attack chain has been found directing victims through multiple rounds of CAPTCHA and intermediate pages that are designed to lend the scheme a veneer of legitimacy, at the same time keeping out automated defenses.

Ultimately, it ends with a sign-in experience that leverages adversary‑in‑the‑middle (AiTM) phishing tactics to harvest Microsoft credentials and tokens in real-time, effectively allowing the threat actors to bypass multi-factor authentication (MFA). The final destination, per Microsoft, depends on whether the malicious flow was triggered from a mobile device or a desktop system.

Phishing Trends in 2026

The disclosure comes as Microsoft's analysis of the email threat landscape between January and March 2026 revealed that QR code phishing emerged as the fastest-growing attack vector, while CAPTCHA-gated phishing evolved "rapidly" across payload types. In all, the tech giant said it detected about 8.3 billion email-based phishing threats.

Of these, nearly 80% were link-based, where large HTML and ZIP files accounted for a huge chunk of the malicious payloads distributed via phishing emails. The end goal of a vast majority of these attacks was credential harvesting, with malware delivery declining to a mere 5-6% by the end of the quarter.

Microsoft also said the operators of the Tycoon 2FA phishing-as-a-service (PhaaS) platform have attempted to shift hosting providers and domain registration patterns following a coordinated disruption operation in March 2026.

"Toward the end of March, we saw Tycoon 2FA moving away from Cloudflare as a hosting service and now hosts most of its domains across a variety of alternative platforms, suggesting the group is attempting to find replacement services that offer comparable anti-analysis protections," it added.

In a report published back in February, Palo Alto Networks Unit 42 highlighted how threat actors are abusing QR codes as URL shorteners to disguise malicious destinations, in-app deep links to steal account credentials, and bypass app store security by linking to direct downloads of malicious apps.

Data from Microsoft shows a massive surge in QR code phishing during the three-month time period, as attack volumes jumped from 7.6 million in January to 18.7 million in March, representing a 146% increase. One notable development observed in late March was the use of QR codes embedded directly in email bodies.

Business email compromise (BEC) scams, on the other hand, exhibited more fluctuations, crossing more than 4 million in attack volume in March 2026, up from over 3.5 million in January and more than 3 million in February. Collectively, 10.7 million BEC attacks were recorded.

Two noteworthy campaigns observed during Q1 2026 are below -

  • A large, sustained campaign between February 23 and February 25, 2026, that sent more than 1.2 million messages to users at more than 53,000 organizations in 23 countries, using 401(k)-, payment-, and invoice-themed lures to serve an SVG attachment. Opening the file directed the victims to a CAPTCHA check, successfully completing which, they were shown a fake sign-in page to compromise their accounts.
  • A massive campaign on March 17, 2026, that involved more than 1.5 million confirmed malicious messages sent to over 179,000 organizations across 43 countries. The activity accounted for 7% of all malicious HTML attachments observed in the month. When opened, the HTML file redirected victims to an initial phishing page that screened the visitor before routing them to the final destination: a phishing page that presented a CAPTCHA challenge before serving a fraudulent sign‑in page.

Cybersecurity

"Interestingly, although messages in this campaign shared common tooling, structure, and delivery characteristics, the infrastructure hosting the final phishing payload was linked to multiple different PhaaS providers," Microsoft said. "Most observed phishing endpoints were associated with Tycoon 2FA, while additional activity was linked to Kratos (formerly Sneaky 2FA) and EvilTokens infrastructure."

The findings coincide with the emergence of phishing and BEC campaigns that abuse Amazon Simple Email Service (SES) as a delivery vector to bypass SPF, DKIM, and DMARC checks, and facilitate credential theft via phony sign-in pages. These attacks often work by gaining access to Amazon SES through leaked AWS access keys.

"The insidious nature of Amazon SES attacks lies in the fact that attackers aren't using suspicious or dangerous domains; instead, they are leveraging infrastructure that both users and security systems have grown to trust," Kaspersky said.

"By weaponizing this service, attackers avoid the effort of building dubious domains and mail infrastructure from scratch. Instead, they hijack existing access keys to gain the ability to blast out thousands of phishing emails. These messages pass email authentication, originate from IP addresses that are unlikely to be blocklisted, and contain links to phishing forms that look entirely legitimate."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.