May 27, 2020 By David Bisson 2 min read

Malicious actors leveraged phishing emails designed to look like they originated from the Supreme Court in order to steal victims’ Office 365 credentials.

Armorblox detected a phishing campaign that attempted to steal victims’ Office 365 credentials by masquerading as a subpoena from the Supreme Court. The attack emails sent via this operation leveraged “Supreme Court” as their sender name along with authoritative language to trick recipients into clicking on a “View subpoena” button. This button redirected recipients to a phishing page hosted on the domain “invoicesendernow[.]com” for the purpose of stealing their Office 365 credentials.

A closer look revealed that this operation employed multiple techniques to bypass email gateways and other security controls. First, it targeted only a few users in each organization to avoid raising red flags. Second, the campaign’s penultimate redirect sent users to a functioning CAPTCHA page. This asset added legitimacy to the operation as well as helped it to evade detection by email security technologies.

Other Recent Attempts to Steal Office 365 Credentials

Back in December 2019, PhishLabs spotted a similar campaign that leveraged a malicious Office 365 app in order to steal access to a victim’s account without lifting their credentials. That was about a month before Avanan revealed that it had discovered malicious actors abusing Microsoft Sway to target users’ Office 365 details. In April 2020, Group-IB detailed the efforts of one “PerSwaysion” campaign to abuse Microsoft Sway as a means of redirecting users to a fake Office 365 login page.

Defend Against a Phishing Attack

Security professionals can help their organizations defend against a phishing attack by conducting ongoing security awareness training with their employees. These exercises can help educate the workforce about some of the most common types of phishing attacks in circulation today. In addition to human controls, infosec personnel should leverage technical measures that help block email messages from blacklisted and/or typosquatting domains.

More from

Cybersecurity dominates concerns among the C-suite, small businesses and the nation

4 min read - Once relegated to the fringes of business operations, cybersecurity has evolved into a front-and-center concern for organizations worldwide. What was once considered a technical issue managed by IT departments has become a boardroom topic of utmost importance. With the rise of sophisticated cyberattacks, the growing use of generative AI by threat actors and massive data breach costs, it is no longer a question of whether cybersecurity matters but how deeply it affects every facet of modern operations.The 2024 Allianz Risk…

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today