Hackers are utilizing a sophisticated method involving legitimate office.com links combined with Active Directory Federation Services (ADFS) to redirect users to convincing phishing pages for stealing Microsoft 365 credentials. This new technique bypasses traditional security measures by exploiting trusted domains within Microsoft’s infrastructure. #ADFS #PhishingRedirects
Keypoints
- The attack employs legitimate office.com links to deceive users and facilitate phishing redirects.
- Hackers set up custom Microsoft tenants with ADFS to control authentication requests.
- The phishing campaign redirect targets are selectively validated to avoid detection and increase success.
- The attack leverages Microsoft’s trusted infrastructure to bypass URL-based detection and multi-factor authentication.
- Researchers recommend monitoring ADFS redirects and ad parameters to identify malicious activity.