Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Legitimate Microsoft login exploited in phishing campaign

Barracuda illustrates new phishing attacks against Microsoft 365 where attackers use advanced phishing methods to steal session IDs and login credentials via legitimate Microsoft logins. Barracuda illustrates new phishing attacks against Microsoft 365 where attackers use advanced phishing methods to steal session IDs and login credentials via legitimate Microsoft logins.
Barracuda's latest report shows how cybercriminals are using advanced phishing campaigns, legitimate Microsoft logins, and new techniques to steal session IDs, user accounts, and sensitive corporate information.

Attackers are using real Microsoft logins, hiding phishing links in PDF attachments, and using various methods to bypass security controls in email environments, according to Barracuda Networks’ latest Email Threat Radar report, which details several recent attacks targeting organizations and their employees.

One of the attacks described involves attackers using Tycoon 2FA, a phishing platform as a service, and a legitimate Microsoft sign-in page instead of a fake one. The goal is to get the user to sign in and thereby capture session tokens and credentials, which can provide access to email, files, and Microsoft 365 services.

The attack begins with an email warning that the inbox is about to fill up. The message contains a calendar invitation to a purported meeting with Microsoft's security team and a button to release held emails.

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

The button leads to a Microsoft login that is genuine, but accessed via the attackers’ own registered application in the Tycoon 2FA platform. When the user logs in, the session ID is captured. In the next step, the user is prompted to enter their credentials on a fake page, which also allows the attackers to access the password.

Links are hidden in PDF attachments
The report also describes attacks where suspicious links have been moved from the email body to a PDF attachment.

The campaign analyzed asks the recipient to open an attachment related to, for example, regulatory compliance or payments. The link in the document leads to an authentication process that resembles a legitimate login and collects user credentials and email address.

In these cases, device codes are generated locally in the browser instead of using real Microsoft APIs. This mimics the process used to associate devices with Microsoft accounts. The scam also uses CAPTCHAs and phishing pages that expire after a certain period of time.

Button with two different outcomes in the same email
Another attack uses a so-called ”split-click” technique, where the same button has different functions depending on where the user clicks.

In the observed case, clicking on the upper part of the button leads to a legitimate Microsoft page, while the lower part leads to a phishing page via a so-called blob URL generated in the browser.

Phishing is also used to spread malware
According to the report, phishing is in some cases also used to deliver malicious code, in addition to collecting login details.

Among the examples highlighted are:

  • files that appear to be harmless PDF documents but actually contain JavaScript, where the script hides its malicious code in the fake document using steganography and code obfuscation techniques
  • Campaigns where attackers impersonate a government agency and distribute scripts that download additional code and execute it in memory using Windows components
  • Multi-step attacks where the user is led through multiple pages, for example from an HTML file to a fake OneDrive and then to a login page

Recommendations from Barracuda
The report highlights Barracuda the following measures:

  • protect identities and session IDs, not just passwords
  • expand threat detection capabilities to include calendar invitations, attachments, and login flows
  • use behavior-based detection
  • invest in protection for attachments and clients
  • enables rapid incident response
  • update training courses to reflect current phishing methods

The report is based on analyses from Barracuda Research.

Read more here »

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED