New phishing campaign is impersonating the delivery giant

computing

(Image credit: Shutterstock)

A new phishing campaign has been uncovered impersonating logistics giant DHL to try and steal Microsoft 365 credentials from victims in the education industry, experts has claimed.

Cybersecurity researchers from Armorblox recently discovered a major phishing campaign, with more than 10,000 emails sent to inboxes belonging to a “private education institution”. 

The email is made to look as if it’s coming from DHL: it carries the company branding as well as tone of voice one might associate with the shipping giant. In the email, titled “DHL Shipping Document/Invoice Receipt” the recipient is informed that a customer sent a parcel to the wrong address and that the correct delivery address needs to be provided.

Fake login popup

The email obviously comes with an attachment, conveniently titled “Shipping Document Invoice Receipt” which, if opened, looks like a blurred-out preview of a Microsoft Excel file. 

Over the blurred-out document pops up a Microsoft login page, trying to trick the victims into thinking they need to log into their Microsoft 365 accounts in order to view the contents of the file. Should the victims provide the login credentials, they’d go straight to the attackers.

Read more

> New service makes it easier than ever for rookies to launch Microsoft 365 phishing attacks
> This Microsoft 365 phishing campaign is using some crafty US government lures
> Check out the best firewalls around (opens in new tab)

“The email attack used language as the main attack vector in order to bypass both Microsoft Office 365 and EOP email security controls,” Armorblox explained. “These native email security layers are able to block mass spam and phishing campaigns and known malware and bad URLs. However, this targeted email attack bypassed Microsoft email security because it did not include any bad URLs or links and included an HTML file that included a malicious phishing form.”

As the researchers said, the attackers used a valid domain which allowed them to bypass Microsoft’s email (opens in new tab) authentication checks. 

The best way for businesses to protect against phishing attacks is to train their employees to spot red flags in their inboxes, such as the sender’s email address, typos and spelling errors in the email, the sense of urgency (legitimate emails will almost never require the user to react urgently), and unexpected links/attachments. 

    Via: SiliconAngle (opens in new tab)

    Are you a pro? Subscribe to our newsletter

    Sign up to theTechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    By submitting your information you agree to the Terms & Conditions (opens in new tab) and Privacy Policy (opens in new tab) and are aged 16 or over.

    Sead Fadilpašić

    Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

    TECH NEWS RELATED

    9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    Watching movies online can be a hassle; Especially when there is a lot of buffering. This is one of the biggest reasons for people to download their movies and watch them offline. However, I found this specific query in a forum where people were asking to recover a downloaded movie ...

    View more: 9 Best Ways To Retrieve A Downloaded Movie On Your Laptop

    How To Snip Screen On Your Laptop?

    Taking a screenshot is not a complicated process. All of us are familiar with at least one way to do it. However, there are several ways to capture your screen for a frame. We made this article to show you all the different ways you can grab your screens. If ...

    View more: How To Snip Screen On Your Laptop?

    How To Connect AirPods To A Laptop?

    The Apple AirPods are, undoubtedly, some of the best earpieces available on the electronics market. With three generations of different AirPods models, these sleek, ivory earphones are quite popular. Apart from the appearance and quality, AirPods are known for being versatile. Irrespective of what the host device is, AirPods can ...

    View more: How To Connect AirPods To A Laptop?

    7 Best Ways To Fix DistributedCOM Error In Windows

    If you open the Event Viewer utility often, you may notice a DistributedCOM Error on Windows. Let’s know what this DistributedCOM Error Windows error is, how it’s caused, and how you can fix it. Contents show 1 What Is the DistributedCOM Error Windows 10 and 11? 2 What is the ...

    View more: 7 Best Ways To Fix DistributedCOM Error In Windows

    12 Easy Fixes For Webcam Not Working In Windows

    Cameras are becoming quite common for PCs. We use meetings on Zoom, Microsoft Teams, Skype, and other options. The operating system might not be at fault if your camera isn’t working. You can use the given solutions to solve the Webcam Not Working Windows issue quickly. We have covered ...

    View more: 12 Easy Fixes For Webcam Not Working In Windows

    Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Is  Windows 10 Sound Not Working on your PC? This is a common issue faced by many Windows users.  If you are one among them, you are in the right place. This article gives you 11 solutions to fix the no-sound issues in Windows 10.  Contents show 1 Reasons For ...

    View more: Windows 10 Sound Not Working: 18 Quick And Easy Methods

    Fix CAA20004 Microsoft Teams Sign in Error

    Microsoft Teams have a bundle of excellent and attractive features that provides you with easy communication among friends, even classes and offices were conducted online. There’s a lot going on in MS Teams, for example, you can chat via messages and video calls, and at the same time share files ...

    View more: Fix CAA20004 Microsoft Teams Sign in Error

    How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows standalone updates packages are useful when your Windows updater is not working or you want to install a certain update manually. However, running these updated packages, sometimes, shows the error message “This update is not applicable to your computer” or “This update is not applicable to your computer”. ...

    View more: How To Fix This Update Is Not Applicable To Your Computer Error: 11 Quick Fixes

    Windows Dual Boot Menu Not Showing: 6 Easy Ways To Fix

    12 Best Fixes: Windows 10 Start Menu Search Not Working

    How to customize and publish a Microsoft Bookings page?

    Chic-Fil-A’s Training Program Apparently Features a Familiar Fallout Face

    Microsoft Teams Status not updating or changing

    Don’t Buy a Foldable Until Samsung Brings This Prototype to Life

    Windows Encryption Not Working? 6 Best Ways To Fix

    How to get Apple Calendar on Windows PC

    Windows Update Error 0x80073701: 9 Best Ways To Fix

    Best Ways To Fix Slow Internet During VPN On Windows 11

    6 Solutions To Fix Wmpnetwk High CPU Usage In Windows

    Save Time in Microsoft PowerPoint by Making Your Own Theme

    OTHER TECH NEWS

    Top Car News Car News