CYBERSECURITY

Microsoft 365 Users Targeted by Sophisticated Fake IT and Phishing Campaigns

Microsoft 365 Users Targeted by Sophisticated Fake IT and Phishing Campaigns

Security researchers note the calls are highly polished, with scripts tailored

Global businesses face rising threats as cybercriminals deploy deceptive tactics to steal credentials and data through Microsoft 365 platforms, exploiting trust in internal support systems. Two coordinated campaigns, identified as BigBear 2.0 and PREY-0058, are actively targeting employees worldwide with fraudulent phone calls posing as IT support and convincing phishing emails designed to mimic legitimate Microsoft communications. These attacks aim to trick users into revealing login credentials or installing malicious software under the guise of routine security updates or account verification. How the Fake IT Support Scam Operates Attackers initiate contact via phone, claiming to be from Microsoft or internal IT teams, often using spoofed numbers to appear legitimate. They create urgency by alleging suspicious activity on the user’s account, then guide victims to fake login pages or remote access tools. Once access is granted, attackers can exfiltrate data, deploy ransomware, or move laterally within corporate networks.

Security researchers note the calls are highly polished, with scripts tailored to mimic corporate helpdesk procedures. Why Phishing Emails Remain Effective Against M365 Users The phishing emails in these campaigns use authentic-looking Microsoft branding, urgent subject lines about account security or policy changes, and links to near-identical replicas of official login portals. Victims who enter their credentials unknowingly hand them over to attackers. Unlike broad spam, these messages are often personalized, referencing real projects or internal terminology gathered from prior breaches or social media reconnaissance, increasing their credibility. What Makes These Campaigns Particularly Dangerous? Both BigBear 2.0 and PREY-0058 demonstrate a high level of operational sophistication, combining social engineering with technical evasion techniques to bypass standard email filters and endpoint protections. The use of voice phishing (vishing) alongside traditional email attacks creates a multi-vector threat that exploits human psychology as much as technical vulnerabilities.

Experts warn that even security-aware employees can be deceived when under pressure or distracted. Frequently Asked Questions How can employees distinguish a real IT call from a fake one? Legitimate IT departments will never ask for passwords or request remote access via unsolicited calls. Employees should hang up and contact their IT team through official channels to verify any such request. What signs indicate a phishing email targeting Microsoft 365? Check for subtle URL misspellings, unexpected attachments, and pressure tactics like threats of account closure. Always hover over links to see the true destination before clicking. Are multi-factor authentication methods still effective against these attacks? While MFA significantly reduces risk, attackers are increasingly using real-time phishing proxies to intercept codes. Users should remain vigilant and report any unexpected MFA prompts.

Content written by Priya Nair for tech-site.news editorial team, AI-assisted.

Comments

Leave a comment