Kaspersky Blocks 31,000 Scam Emails Exploiting Microsoft Authentication System in Seven Weeks

Share f X WA in

ISLAMABAD: Cybersecurity firm Kaspersky has reported blocking more than 31,000 scam emails exploiting Microsoft’s authentication system over seven weeks, warning that cybercriminals are using legitimate Microsoft services to redirect unsuspecting users to fraudulent websites and potentially malicious downloads.

According to Kaspersky researchers, the emails were detected between August 1 and September 18. The campaign targets email users through deceptive messages that appear to originate from trusted Microsoft services, making fraudulent links more difficult to identify.

The researchers said attackers are exploiting features of Microsoft Entra, the company’s identity and access management platform, to create convincing phishing messages. The emails typically ask recipients to update their account credentials or electronically sign documents.

How Scammers Exploit Microsoft Entra Authentication

Kaspersky explained that cybercriminals begin by creating a Microsoft account and accessing the Microsoft Entra admin center, where they register a new application.

During registration, the platform allows administrators to specify a redirect URI, which determines where users are directed after completing authentication.

Attackers exploit this feature by entering the address of a fraudulent website as the redirect destination. They then distribute emails containing legitimate Microsoft authentication links associated with the registered application.

When recipients click these links, they can be redirected to websites designed to steal personal information or distribute malicious software.

The technique allows cybercriminals to use genuine Microsoft infrastructure as part of their phishing campaigns, potentially making suspicious links appear more trustworthy.

Fraudulent Messages Hidden in Genuine Microsoft Notifications

Kaspersky researchers also identified another technique in which attackers manipulate Microsoft Entra account information to insert fraudulent messages into legitimate service notifications.

According to the company, attackers may obtain access through a low-cost subscription or trial account before entering deceptive text into the name field of the Microsoft Entra Overview page.

They subsequently create fictitious user accounts with fabricated email addresses, display names and passwords.

Using these accounts, the attackers access the Microsoft My Account portal and enter a targeted individual’s real email address as a backup contact for password recovery.

This process triggers a genuine Microsoft verification email to the recipient. However, the message can contain fraudulent text in its subject line and signature, creating an opportunity for scammers to deliver misleading instructions through an official notification.

Why Traditional Phishing Warning Signs May Not Work

Kaspersky said the campaign demonstrates how attackers increasingly misuse legitimate online services rather than relying exclusively on forged email addresses or counterfeit websites.

Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky, said the use of official services gives fraudulent communications an additional appearance of credibility.

He noted that conventional phishing warning signs may be less effective when suspicious messages are delivered through trusted platforms, making such attempts difficult for individuals to recognize without additional protection.

The company previously identified a separate phishing campaign involving the misuse of Microsoft’s authentication mechanism earlier this year.

Its latest findings indicate that attackers are continuing to exploit the same underlying technology while changing the messages and techniques used to approach potential victims.

Kaspersky Recommends Stronger Email Security Measures

Following the findings, Kaspersky advised organizations to strengthen email security controls and deploy protection capable of identifying sophisticated phishing attempts.

The company highlighted Kaspersky Security for Mail Server as one of its solutions for protecting corporate email environments against malicious messages and other email-based threats.

For individual users, it pointed to the anti-phishing capabilities available in Kaspersky Premium.

The findings underline the risks associated with fraudulent communications that originate through legitimate digital services, particularly when recipients are encouraged to follow authentication links, provide account information or download files.