National Cyber Warfare Foundation (NCWF)

Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud


0 user ratings
2026-08-20 10:46:14
milo
Red Team (CNA)

Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View […]


The post Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Mayura Kathir

Source: gbHackers
Source Link: https://gbhackers.com/microsoft-365-inbox-rules/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.