< Back to all clusters
[TECHNOLOGY] · Germany · 7 sources

started · updated

Microsoft phishing campaigns exploit real login pages and spoof security emails

Security researchers warn that phishing attacks are increasingly using authentic Microsoft login pages to trick users. Over 200 fake Teams messages were sent to employees in about 120 organisations, appearing to come from internal HR channels and directing recipients to a genuine Microsoft sign‑in page before requesting permissions for a malicious application. The campaign relies on trusted Microsoft domains, making traditional indicators such as suspicious URLs less reliable.

Guidance on identifying genuine Microsoft security notifications emphasizes checking the sender address (e.g., reply@accountprotection.microsoft.com), scrutinising links, and verifying SPF, DKIM and DMARC results. Messages from onmicrosoft.com domains are not automatically trustworthy.

In parallel, new malware such as Lumma Stealer is being distributed via counterfeit film‑download files (e.g., "the odyssey 2026 1080p h264‑djt.exe"). The stealer harvests passwords, browser data, crypto‑wallet credentials and even two‑factor authentication tokens, targeting Windows users, gamers and cryptocurrency holders.

Entities

Bitdefender · Check Point Research · Lumma Stealer · Microsoft Corporation · Microsoft Teams