惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
A
About on SuperTechFans
月光博客
月光博客
Jina AI
Jina AI
F
Fortinet All Blogs
博客园 - 聂微东
The Cloudflare Blog
美团技术团队
B
Blog RSS Feed
N
Netflix TechBlog - Medium
罗磊的独立博客
The GitHub Blog
The GitHub Blog
I
InfoQ
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Apple Machine Learning Research
Apple Machine Learning Research
H
Help Net Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
T
The Blog of Author Tim Ferriss
MyScale Blog
MyScale Blog
博客园 - 三生石上(FineUI控件)
宝玉的分享
宝玉的分享
阮一峰的网络日志
阮一峰的网络日志
V
V2EX

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Microsoft Flags Mass Phishing Campaign Using Fake Complia...
Beth Maundrill · 2026-05-05 · via www.infosecurity-magazine.com

A phishing campaign targeting more than 35,000 users across 13,000 organizations has been identified by the Microsoft Defender Research team.

The large-scale credential theft campaign used fake internal compliance or regulatory communications as lures for the campaign.

The lures in this campaign used polished, enterprise-style HTML templates with structured layouts and preemptive authenticity statements, making them appear more credible than typical phishing emails and increasing their plausibility as legitimate internal communications. 

The campaign ran between April 15 and 16, 2026, and primarily targeted US firms, but was identified in organizations across 26 countries total.

Urgent Compliance Phishing Lure

According to Microsoft’s findings, the messages contained concerning accusations and repeated time-bound action prompts. This gave the campaign a sense of urgency and pressure for victims to act.

For example, subject lines included “Internal case log issued under conduct policy” and the messages claimed that a “code of conduct review” had been initiated, and referenced organization-specific names embedded within the text.

The emails instructed recipients to “open the personalized attachment” to review case materials.

The attached PDF encouraged recipients to click the “Review Case Materials” link, this is what initiated the credential harvesting flow.

The attackers designed the message to appear legitimate by claiming it came from an authorized internal channel and that all links and attachments had been securely reviewed.

A green banner claiming the message had been encrypted using Paubox, a legitimate service associated with HIPAA-compliant communications, further reinforced credibility.

When the recipient clicked on the link within the PDF they were redirected to a landing page which displayed a Cloudflare CAPTCHA, presented as a mechanism to validate that the user was coming “from a valid session”. This was likely to deter automated analysis and sandboxes, according to Microsoft.

After passing the CAPTCHA, victims were redirected to another site claiming the documents were encrypted and required account authentication to proceed.

Microsoft observed an attack chain resembling device code phishing but confirmed only the adversary-in-the-middle (AiTM) component.

Victims were led through multiple staged pages with email entries, CAPTCHAs and reassuring status messages before being redirected, based on device type, to a final phishing site.

There, users were prompted to sign in with Microsoft under the guise of a compliance review, triggering an AiTM session hijack to steal authentication tokens and compromise accounts.

Protection Guidance From Microsoft

Microsoft recommended serval mitigations to reduce the impact of this threat, including, but not limited to:

  • Review the recommended settings for Exchange Online Protection and Microsoft Defender for Office 365 to ensure your organization has established essential defenses and knows how to monitor and respond to threat activity
  • Run realistic attack scenarios during awareness training so employees are prepared to spot such phishing attempts
  • Enable password-less authentication methods for accounts that support password-less. For accounts that still require passwords, use authenticator apps like Microsoft Authenticator for multifactor authentication (MFA)
  • Turn on Safe Links and Sade Attachments in Microsoft Defender for Office 365
  • Configure automatic attack disruption in Microsoft Defender XDR