Security News > 2021 > October > How a vishing attack spoofed Microsoft to try to gain remote access

How a vishing attack spoofed Microsoft to try to gain remote access
2021-10-14 18:41

A standard phishing attack typically involves sending people an email or text message spoofing a known company, brand or product in an attempt to install malware or steal sensitive information.

The emails borrowed the look and layout of actual emails from Microsoft and even included information on a subscription for Microsoft Defender Advanced Protection that supposedly was ordered by the recipient.

The emails tried to convey a sense of trust, as it appears to come from Microsoft.

The initial emails described by Armorblox snuck past the Google Workspace email security.

Inspect the sender's name, email address and the language used within the email.

Check for any inconsistencies in the message leading you to ask yourself such questions as: "Why is a Microsoft email being sent from a Gmail account?" and "Why are there no links in the email, even in the footer?".


News URL

https://www.techrepublic.com/article/how-a-vishing-attack-spoofed-microsoft-to-try-to-gain-remote-access/#ftag=RSS56d97e7

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 50 1369 2820 161 4400