Security researchers tracking modern email threats have identified a sophisticated phishing campaign that bypasses traditional detection by misusing legitimate Microsoft cloud services, according to findings published by Kaspersky.
Kaspersky Findings on Microsoft Cloud Services Phishing
Rather than relying entirely on external infrastructure, attackers use legitimate Microsoft Entra authentication mechanisms to route targets toward attacker-controlled domains.
Microsoft Entra Admin Center Redirect Attack Mechanism
The mechanics of the attack begin inside the Microsoft Entra admin center. Fraudsters create a Microsoft account, log into the management portal, and generate a new application registration. During registration, the operator inserts a malicious URL into the redirect address field. When victims receive and click the official Microsoft-generated redirect link containing the application ID and preset address, they are ushered straight to a hostile landing page built to harvest credentials or push malware.
Fake Notifications Masked as Official Alerts
Investigators also documented a separate vector abusing the Microsoft Entra admin center via legitimate service notifications. Attackers insert fabricated messages into the name field of the service overview page and set up dummy user profiles with manufactured information.

Using these rogue profiles, the operators log into the Microsoft account portal and register the victim’s genuine email address as a backup contact. This triggers an unsolicited verification code sent directly to the target, while the fraudster’s custom text embeds itself directly into the email subject line and signature.
Andrey Kovtun on Credibility and Traditional Phishing Indicators
Using these official services to send out phishing links and messages raises their credibility and makes them much harder to spot, meaning traditional phishing indicators might not be enough on their own.
To counter these complex threats, Kaspersky advises organizations to deploy advanced email security tools underpinned by machine learning, behavioral monitoring, and strong identity theft and data leak detection systems.