Microsoft Warns of Sophisticated SharePoint-Based Phishing Campaign Targeting the Energy Sector

Listen to this Post

Featured Image

Introduction

Microsoft has uncovered a highly coordinated and technically mature phishing operation targeting organizations across the energy sector, exposing how modern cybercrime is evolving beyond simple credential theft. The campaign blends adversary‑in‑the‑middle (AitM) phishing techniques with business email compromise (BEC), abusing trusted enterprise services like SharePoint to bypass security controls and remain invisible inside victim organizations. The findings highlight a growing reality: attackers no longer need exotic malware or zero‑day exploits when legitimate platforms, identities, and user trust can be weaponized at scale.

the Original

Microsoft’s investigation reveals a multi‑stage phishing and BEC campaign that relies heavily on trust exploitation rather than brute force. The attack typically begins with a phishing email sent from an already compromised account belonging to a trusted organization. These emails impersonate legitimate SharePoint file‑sharing notifications, making them appear routine and credible to recipients inside enterprise environments.

Because SharePoint and OneDrive are deeply embedded into daily business workflows, the messages rarely trigger suspicion or automated defenses. This technique, known as living‑off‑trusted‑sites (LOTS), allows attackers to deliver malicious links without deploying their own infrastructure. When a victim clicks the link, they are redirected to a fake document access page that harvests credentials and session cookies in real time through an AitM setup.

Once access is gained, the attackers move quickly to establish persistence. They create inbox rules that automatically delete incoming emails and mark messages as read, effectively blinding the victim to any unusual activity or security alerts. Using the compromised mailbox, the attackers then launch internal and external phishing campaigns, impersonating the victim to target coworkers, partners, and contacts outside the organization.

In at least one observed case, more than 600 phishing emails were sent from a single compromised account. The attackers actively managed the mailbox, deleting bounce messages, removing out‑of‑office replies, and even reassuring recipients who questioned the legitimacy of the emails. All correspondence was later erased to minimize traces of the operation.

Microsoft emphasizes that password resets alone are insufficient to stop this kind of attack. Because session cookies remain valid, organizations must revoke active sessions, remove malicious inbox rules, and roll back unauthorized MFA changes. Microsoft worked directly with affected customers to perform these actions, but the total number of compromised organizations and the identity of the threat actors remain unknown.

The disclosure aligns with broader industry findings. Okta recently reported the rise of phishing‑as‑a‑service kits designed for voice phishing campaigns. These kits enable attackers, posing as technical support staff, to guide victims through real‑time credential theft and MFA bypasses using synchronized browser manipulation and social engineering. Additional campaigns have abused deceptive URL structures and homoglyph attacks, further illustrating how subtle visual tricks continue to fool even security‑aware users.

What Undercode Say:

This campaign is a textbook example of how modern cyberattacks have shifted from technical exploitation to psychological and operational manipulation. What makes this operation dangerous is not innovation in malware, but innovation in trust abuse. By embedding themselves inside legitimate workflows like SharePoint document sharing, attackers effectively turn enterprise productivity tools into delivery mechanisms for compromise.

The energy sector is a particularly attractive target due to its complex supply chains, high‑value communications, and dependence on third‑party collaboration. Once a single trusted account is compromised, the attacker gains access to a web of relationships that can be exploited laterally. This is not just phishing; it is identity‑driven intrusion.

AitM attacks represent a critical escalation because they neutralize traditional defenses. MFA, long promoted as a silver bullet, becomes ineffective when attackers intercept authentication flows and session tokens in real time. The persistence techniques described, especially inbox rule manipulation, demonstrate a deep understanding of enterprise email systems and human behavior.

The operational discipline shown by the attackers is notable. Actively managing inboxes, responding to skeptical recipients, and cleaning up artifacts suggests a semi‑professional or professional operation rather than opportunistic crime. These behaviors are consistent with financially motivated groups that understand how to remain invisible while scaling their reach.

Another key takeaway is the increasing convergence of phishing, BEC, and social engineering. The boundary between technical attack and human manipulation has all but disappeared. Voice phishing kits, real‑time browser control, and Telegram‑based credential relays show how attackers are industrializing deception as a service.

Defensively, this reinforces the need for identity‑centric security strategies. Session revocation, phishing‑resistant MFA, continuous access evaluation, and behavioral email monitoring are no longer optional. Organizations must also treat inbox rules, OAuth permissions, and MFA changes as high‑risk events worthy of immediate investigation.

Ultimately, the campaign underscores a harsh truth: trusted platforms are now part of the attack surface. As long as users rely on familiar brands and workflows, attackers will continue to exploit that trust. Security awareness alone is insufficient; structural controls must assume compromise and focus on rapid detection and containment rather than prevention alone.

Fact Checker Results

Microsoft has publicly confirmed the existence of the campaign and its technical characteristics.
The abuse of SharePoint and inbox rules aligns with known BEC and AitM tactics observed across industries.
Claims regarding MFA bypass are consistent with documented limitations of non‑phishing‑resistant MFA methods.

Prediction

AitM‑driven phishing campaigns will increasingly replace traditional credential harvesting as the dominant attack model against enterprises. Attackers will continue abusing trusted SaaS platforms to blend into normal business traffic, while phishing‑as‑a‑service ecosystems mature further. Organizations that fail to adopt session‑level identity controls and phishing‑resistant authentication will see higher rates of silent, long‑term compromise rather than loud, easily detectable breaches.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: thehackernews.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon