Hackers Exploit Microsoft 365’s Direct Send Feature for Internal Phishing Attacks

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
969
4,663
2,168
Germany
Threat actors are leveraging Microsoft 365’s Direct Send feature to launch sophisticated phishing campaigns that mimic internal organizational emails, eroding trust and heightening the success rate of social engineering exploits.

This feature, designed for unauthenticated relaying of messages from devices like multifunction printers and legacy applications to internal recipients, allows external attackers to spoof sender addresses without requiring valid credentials.

Proofpoint researchers have documented an ongoing operation where adversaries inject phishing emails via unsecured third-party email security appliances acting as SMTP relays, often hosted on virtual private servers (VPS).
Full Story on: