The Hacker News
Read post

Microsoft Flags Multi-Stage AitM Phishing and BEC Attacks Targeting Energy Firms

Microsoft has identified a sophisticated multi-stage phishing campaign targeting energy sector organizations. Attackers abuse SharePoint file-sharing to deliver phishing payloads, steal credentials and session cookies through adversary-in-the-middle techniques, then create inbox rules to maintain persistence. The compromised accounts are used to send large-scale phishing emails to internal and external contacts. Password resets alone cannot stop these attacks; organizations must revoke active session cookies and remove malicious inbox rules. The campaign exemplifies the growing trend of abusing trusted platforms like SharePoint, Google Drive, and AWS to appear legitimate and evade detection.

    #cyber#microsoft#authentication#phishing#sharepoint
Jan 23•6m read time•From thehackernews.com
Post cover image
45 Impressions
The Hacker News's image
The Hacker News

The Tidyverse Blog offers insights, tutorials, and updates on the Tidyverse, a collection of R packa...

2.3K Followers

•

1.7K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard