Microsoft 365 ‘Direct Send’ abused to send phishing as internal users

Microsoft 365 ‘Direct Send’ abused to send phishing as internal users

This article discusses a phishing campaign exploiting the β€œDirect Send” feature in Microsoft 365 to bypass security filters and steal credentials. It highlights the risks of misconfigured Direct Send and provides mitigation strategies, including disabling the feature and implementing strict email policies. #Microsoft365 #DirectSend #PhishingCampaign #PowerShell #EmailSecurity

Keypoints

  • The phishing campaign has targeted over 70 organizations primarily in the United States across various sectors.
  • Attackers use PowerShell commands to send emails via the smart host, impersonating internal communications without authentication.
  • Phishing emails often contain PDF attachments with QR codes linking to fake Microsoft login pages to steal credentials.
  • Microsoft recommends disabling the β€œReject Direct Send” setting in Exchange to prevent abuse.
  • Implementing strict DMARC policies, enforcing SPF hardfail, and employee training are critical mitigation steps.

Read More: https://www.bleepingcomputer.com/news/security/microsoft-365-direct-send-abused-to-send-phishing-as-internal-users/