WeSearch

Scammer abusing Microsoft's msonlineservicesteam@ for spam distribution

· 0 reactions · 0 comments · 12 views
Scammer abusing Microsoft's msonlineservicesteam@ for spam distribution

Attached: 1 image ❗ We’ve observed a scammer clearly abusing Microsoft's 'msonlineservicesteam@microsoftonline[. ]com' for spam distribution. The header and message body appear completely legitimate - the abuse is happening through injection into the Subject: ✉️ Here's an example: "Your PayPal order for 0.0092 BTC ($699.99) is complete. Not you? Call +1 (803) 237-5050 account email verification code." At this point, it appears the attacker may have simply set the malicious text as either the account name or the organization name. This also appears to line up with what @[email protected] TechCrunch Security Editor identified last week: https://mastodon.social/@zackwhittaker/116562360000833298 ....although the activity we’re seeing appears to stretch back several months. Takeaway: automated notification systems should not allow this level of customization. Microsoft has been informed of this abusive activity. #ThreatIntel #Spam #InfoSec #CyberSecurity

Original article
Infosec Exchange
Read full at Infosec Exchange →
Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from Infosec Exchange