Complex Mathematics

Hackers are stealing Microsoft 365 accounts by abusing link-wrapping services




  • Crooks are using link wrapping services to entice victims into clicking
  • The links redirect the victims to a fake Microsoft 365 landing page
  • The campaign has been going on for at least two months

Cybercriminals are abusing Proofpoint’s and Intermedia’s “link wrapping” service to bypass email protections, create convincing phishing emails, and ultimately – steal people’s Microsoft 365 credentials. This is according to cybersecurity researchers from Cloudflare, who have been observing such campaigns in the wild for at least two months.

Proofpoint’s link‑wrapping service, known as URL Defense, protects users by rewriting every inbound email link to route through Proofpoint’s inspection gateway before it reaches the actual recipient. When a person clicks a link in an email, it is evaluated in real-time (including sandbox detonation and reputation checks) and is only granted access if the link is deemed safe.



Source link


Discover more from cplexmath tech stop

Subscribe to get the latest posts sent to your email.

Discover more from cplexmath tech stop

Subscribe now to keep reading and get access to the full archive.

Continue reading