Friday, October 9, 2026 Latest Mohamed Salah Returns to Trabzonspor Training Ahead of Samsunspor Clash Our standards
Technology

Kaspersky: Attackers Exploit Microsoft Entra to Send Phishing Emails

Security researchers tracking modern email threats have identified a sophisticated phishing campaign that bypasses traditional detection by misusing legitimate Microsoft cloud…

Kaspersky: Attackers Exploit Microsoft Entra to Send Phishing Emails
Kaspersky: Attackers Exploit Microsoft Entra to Send Phishing Emails

Security researchers tracking modern email threats have identified a sophisticated phishing campaign that bypasses traditional detection by misusing legitimate Microsoft cloud services, according to findings published by Kaspersky.

Kaspersky Findings on Microsoft Cloud Services Phishing

Rather than relying entirely on external infrastructure, attackers use legitimate Microsoft Entra authentication mechanisms to route targets toward attacker-controlled domains.

Microsoft Entra Admin Center Redirect Attack Mechanism

The mechanics of the attack begin inside the Microsoft Entra admin center. Fraudsters create a Microsoft account, log into the management portal, and generate a new application registration. During registration, the operator inserts a malicious URL into the redirect address field. When victims receive and click the official Microsoft-generated redirect link containing the application ID and preset address, they are ushered straight to a hostile landing page built to harvest credentials or push malware.

Fake Notifications Masked as Official Alerts

Investigators also documented a separate vector abusing the Microsoft Entra admin center via legitimate service notifications. Attackers insert fabricated messages into the name field of the service overview page and set up dummy user profiles with manufactured information.

Kaspersky: Attackers Exploit Microsoft Entra to Send Phishing Emails

Using these rogue profiles, the operators log into the Microsoft account portal and register the victim’s genuine email address as a backup contact. This triggers an unsolicited verification code sent directly to the target, while the fraudster’s custom text embeds itself directly into the email subject line and signature.

Andrey Kovtun on Credibility and Traditional Phishing Indicators

Using these official services to send out phishing links and messages raises their credibility and makes them much harder to spot, meaning traditional phishing indicators might not be enough on their own.

To counter these complex threats, Kaspersky advises organizations to deploy advanced email security tools underpinned by machine learning, behavioral monitoring, and strong identity theft and data leak detection systems.

Accuracy matters. See something that needs attention? Read our corrections policy or contact the newsroom.

Technology Editor

Maya Serrano

Maya Serrano is the editorial identity for TellingPointy's Technology desk, covering artificial intelligence, platforms, software, hardware, cybersecurity, and digital policy. Serrano's work translates complex systems without sanding away the important details. Her desk asks who controls a technology, what data and incentives power it, where the real limits sit, and how a product or policy changes the balance among users, companies, governments, and the wider public.