May 27, 2020 By David Bisson 2 min read

Malicious actors leveraged phishing emails designed to look like they originated from the Supreme Court in order to steal victims’ Office 365 credentials.

Armorblox detected a phishing campaign that attempted to steal victims’ Office 365 credentials by masquerading as a subpoena from the Supreme Court. The attack emails sent via this operation leveraged “Supreme Court” as their sender name along with authoritative language to trick recipients into clicking on a “View subpoena” button. This button redirected recipients to a phishing page hosted on the domain “invoicesendernow[.]com” for the purpose of stealing their Office 365 credentials.

A closer look revealed that this operation employed multiple techniques to bypass email gateways and other security controls. First, it targeted only a few users in each organization to avoid raising red flags. Second, the campaign’s penultimate redirect sent users to a functioning CAPTCHA page. This asset added legitimacy to the operation as well as helped it to evade detection by email security technologies.

Other Recent Attempts to Steal Office 365 Credentials

Back in December 2019, PhishLabs spotted a similar campaign that leveraged a malicious Office 365 app in order to steal access to a victim’s account without lifting their credentials. That was about a month before Avanan revealed that it had discovered malicious actors abusing Microsoft Sway to target users’ Office 365 details. In April 2020, Group-IB detailed the efforts of one “PerSwaysion” campaign to abuse Microsoft Sway as a means of redirecting users to a fake Office 365 login page.

Defend Against a Phishing Attack

Security professionals can help their organizations defend against a phishing attack by conducting ongoing security awareness training with their employees. These exercises can help educate the workforce about some of the most common types of phishing attacks in circulation today. In addition to human controls, infosec personnel should leverage technical measures that help block email messages from blacklisted and/or typosquatting domains.

More from

ONCD releases 2024 Report on the Cybersecurity Posture of the U.S.

4 min read - On May 7, the Office of the National Cyber Director (ONCD) released the 2024 Report on the Cybersecurity Posture of the United States. This new document is a report card on how well cyber policy followed the guidelines set by the National Cybersecurity Strategy, introduced in March 2023. Here’s what you need to know about the newly released report. Fundamental shifts in cyber roles Over the past year, the U.S. national cybersecurity posture was driven by the 2023 National Cybersecurity…

CISA wants private industry to publicly commit to Secure by Design

4 min read - The tech industry has the power to protect the world from nation-state threat attacks, cyber crime and those wanting to compromise data and manipulate critical infrastructure. But with this power comes great responsibility, which, to be honest, the tech industry has not been that interested in holding. But at the RSA Conference (RSAC) in San Francisco, the cybersecurity and tech communities took steps to exert some power and take responsibility. They took the Secure by Design pledge, a promise to…

Change Healthcare discloses $22M ransomware payment

3 min read - UnitedHealth Group CEO Andrew Witty found himself answering questions in front of Congress on May 1 regarding the Change Healthcare ransomware attack that occurred in February. During the hearing, he admitted that his organization paid the attacker's ransomware request. It has been reported that the hacker organization BlackCat, also known as ALPHV, received a payment of $22 million via Bitcoin.Even though they made the ransomware payment, Witty shared that Change Healthcare did not get its data back. This is a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today