Security News > 2022 > March > Microsoft Accounts Targeted by Russian-Themed Credential Harvesting

Microsoft Accounts Targeted by Russian-Themed Credential Harvesting
2022-03-01 10:57

Phishing emails to Microsoft users warning of Moscow-led account hacking have started to make the rounds, looking to lift credentials and other personal details.

That's according to Malwarebytes, which uncovered a spate of spam email that name-checks Russian hacking efforts.

We detected something unusual about a recent sign-in to the Microsoft account.

The emails then provide a button to "Report the user," and an unsubscribe option, according to Malwarebytes' Tuesday analysis.

Clicking the button creates a new message with the to-the-point subject line of "Report the user." The recipient's email address references Microsoft account protection.

The mail explicitly targets Microsoft account holders, but the good news is that Outlook is sending the emails directly to the spam folder, according to Malwarebytes.


News URL

https://threatpost.com/microsoft-accounts-targeted-russian-credential-harvesting/178698/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 480 75 2308 5128 264 7775