started · updated
Phishing campaigns spoof Google Ads sync and Microsoft OAuth to steal credentials
Cofense observed a new phishing operation that impersonates Google Ads MMC Sync. Attackers send fake maintenance notifications urging immediate account synchronization. The emails appear to come from Google Ads, but the sender domain is unrelated and the “Complete Sync Account” button redirects users to a malicious blogspot page that captures their login details.
Kaspersky reported a separate campaign abusing Microsoft’s OAuth 2.0 Device Authorization Grant. Victims receive emails posing as a law firm, with a password‑protected PDF that leads to a Microsoft‑hosted URL configured to redirect to a phishing site. The site presents CAPTCHAs before prompting users to copy a one‑time code that attackers have already obtained, allowing them to hijack session tokens and access the victim’s Outlook, OneDrive and Teams data. Both schemes exploit trusted brand branding to trick users into revealing credentials.