Malicious Office 365 Apps Are the Ultimate Insiders

Krebs on Security 2021-05-05

Summary:

Phishers targeting Microsoft Office 365 users increasingly are turning to specialized links that take users to their organization's own email login page. After a user logs in, the link prompts them to install a malicious but innocuously-named app that gives the attacker persistent, password-free access to any of the user's emails and files, both of which are then plundered to launch malware and phishing scams against others.

Link:

https://krebsonsecurity.com/2021/05/malicious-office-365-apps-are-the-ultimate-insiders/

From feeds:

Intel Hub ยป T04 Krebs on Security

Tags:

2.0

Authors:

BrianKrebs

Date tagged:

05/05/2021, 10:18

Date published:

05/05/2021, 08:27