Linchakin

New Phishing Attack on Microsoft 365 Users Leverages Open Redirects to Avoid Detection

 September 16, 2021     No comments   

New Phishing Attack Microsoft 365The use of open redirects from legitimate domains makes phishing emails that much more believable and credible, obfuscating the dangerous nature of these attacks.

In the ongoing saga of attacks on Microsoft 365 users, security analysts at Microsoft recently announced a widespread attack that utilizes open redirects – a technique used in web development to point to the URL visitors of a website should be taken to once the initially-visited page is done processing the visit.

A simple example of an open redirect is the following:

https://example.com/redirect.php?url=http://attacker.com

According to Microsoft, attackers will use a bit more trickery to fool those that choose to hover over links in emails before clicking on them, embedding a malicious URL within what appears to be a trusted URL (note the red portion of the URL below):

Fig4a_openredirect

Source: Microsoft

In many cases, redirects to malicious URLs first take visitors to Google reCAPTCHA pages to further obfuscate the nature of the final destination from security solutions designed to evaluate email links.

While evaluating destination URLs via hovering over links in an email is definitely a good security practice, threat actors are becoming wise to this and are taking steps such as those mentioned above to make it even more difficult to spot a malicious link.

Users should be taught via Security Awareness Training to be more mindful of the actual message being sent – if unsolicited, it should be treated with at least a bit of distrust and scrutiny, being certain it is legitimate before engaging with links – benign or malicious.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • 3rd Oct - Artificial Intelligence in EducationEducation is an important part of life for everyone, and a good education plays a vital role to have a successful life. In order to improve the educat… Read More
  • AutomatedLab - A Provisioning Solution And Framework That Lets You Deploy Complex Labs On HyperV And Azure With Simple PowerShell Scripts AutomatedLab (AL) enables you to setup test and lab environments on Hyper-v or Azure with multiple products or just a single VM in a very short time.… Read More
  • 6 Tips for Creating Engaging Content for Your Digital Signage System Content is a crucial component of a digital signage system. Even if you have the most advanced technology and the largest, clearest screens, if they… Read More
  • Goldie App 2.0.1 – A designer’s ruler with superpowersby NMac Goldie helps you easily visualize or calculate the golden ratio and many other proportions right on your screen. Here are two ways Goldie can… Read More
  • 3rd Oct - Learning code onlineWhat is learning code online? Learning code is a practice of increasing our coding skills and enhances our knowledge. Learning code does not mean tha… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates