This article discusses a phishing campaign exploiting the βDirect Sendβ feature in Microsoft 365 to bypass security filters and steal credentials. It highlights the risks of misconfigured Direct Send and provides mitigation strategies, including disabling the feature and implementing strict email policies. #Microsoft365 #DirectSend #PhishingCampaign #PowerShell #EmailSecurity
Keypoints
- The phishing campaign has targeted over 70 organizations primarily in the United States across various sectors.
- Attackers use PowerShell commands to send emails via the smart host, impersonating internal communications without authentication.
- Phishing emails often contain PDF attachments with QR codes linking to fake Microsoft login pages to steal credentials.
- Microsoft recommends disabling the βReject Direct Sendβ setting in Exchange to prevent abuse.
- Implementing strict DMARC policies, enforcing SPF hardfail, and employee training are critical mitigation steps.