Attackers use “native phishing” with M365 and AI tools

Spread the love
Attackers use “native phishing” with M365 and AI tools

A Varonis blog post by author Tom Barnea, details how attackers are using a tactic called native phishing to bypass security defenses. The article explains that this method leverages trusted internal applications like Microsoft 365 and easy-to-use no-code platforms to deceive users and steal credentials with high success rates.

How native phishing works

Native phishing delivers malicious content using an organization’s own trusted systems, making it feel legitimate to the recipient. The attack begins after a threat actor compromises a single user’s Microsoft 365 credentials. Instead of sending an easily spotted fake email, the attacker uses the compromised account to carry out the attack from within the organization’s environment.

In real-world incidents observed by Varonis Threat Labs, attackers created a malicious OneNote file and saved it in the compromised user’s OneDrive. They then used the built-in OneDrive sharing feature to send a link to this file to hundreds of other employees. The resulting email notification was a legitimate, automated alert from Microsoft, appearing to come from a trusted colleague. This method avoids traditional email scanning for malicious attachments and bypasses human suspicion.

The OneNote application is an effective vehicle for this because it is not subject to Microsoft’s Protected View security feature, its flexible formatting allows for deceptive layouts, and it can embed malicious links. This shifts the attack from technical exploits to social engineering.


Why we might lose our only window into how AI thinks


The role of no-code platforms

Once a user clicks the link in the shared OneNote file, they are redirected to a fake login page that is nearly identical to their company’s real authentication portal. The research highlights that these convincing phishing sites are often built using free, AI-powered no-code platforms.

The report identifies the platform Flazio as the tool used to create a replica login page in one incident. Varonis has also observed attackers using other no-code services like ClickFunnels and JotForm to quickly build and host customized phishing pages with minimal effort or cost. These platforms allow attackers to easily create fraudulent but professional-looking pages designed to steal user credentials.

To defend against these tactics, Varonis provides several recommendations:

  • Enforce MFA and conditional access for all users to reduce the risk of account takeover.
  • Run regular phishing simulations to build awareness and test employee responses.
  • Ensure internal channels for reporting suspicious activity are clear and accessible.
  • Review and tighten Microsoft 365 sharing settings to limit unnecessary internal file exposure.
  • Set alerts for unusual file sharing behavior and monitor traffic to known no-code site builders.

Featured image credit

FAQs

Frequently Asked Questions

What is a Premium Domain Name?   A premium domain name is the digital equivalent of prime real estate. It’s a short, catchy, and highly desirable web address that can significantly boost your brand's impact. These exclusive domains are already owned but available for purchase, offering you a shortcut to a powerful online presence. Why Choose a Premium Domain? Instant Brand Boost: Premium domains are like instant credibility boosters. They command attention, inspire trust, and make your business look established from day one. Memorable and Magnetic: Short, sweet, and unforgettable - these domains stick in people's minds. This means more visitors, better recall, and ultimately, more business. Outshine the Competition: In a crowded digital world, a premium domain is your secret weapon. Stand out, get noticed, and leave a lasting impression. Smart Investment: Premium domains often appreciate in value, just like a well-chosen piece of property. Own a piece of the digital world that could pay dividends. What Sets Premium Domains Apart?   Unlike ordinary domain names, premium domains are carefully crafted to be exceptional. They are shorter, more memorable, and often include valuable keywords. Plus, they often come with a built-in advantage: established online presence and search engine visibility. How Much Does a Premium Domain Cost?   The price tag for a premium domain depends on its desirability. While they cost more than standard domains, the investment can be game-changing. Think of it as an upfront cost for a long-term return. BrandBucket offers transparent pricing, so you know exactly what you're getting. Premium Domains: Worth the Investment?   Absolutely! A premium domain is more than just a website address; it's a strategic asset. By choosing the right premium domain, you're investing in your brand's future and setting yourself up for long-term success. What Are the Costs Associated with a Premium Domain?   While the initial purchase price of a premium domain is typically higher than a standard domain, the annual renewal fees are usually the same. Additionally, you may incur transfer fees if you decide to sell or move the domain to a different registrar. Can I Negotiate the Price of a Premium Domain? In some cases, it may be possible to negotiate the price of a premium domain. However, the success of negotiations depends on factors such as the domain's demand, the seller's willingness to negotiate, and the overall market conditions. At BrandBucket, we offer transparent, upfront pricing, but if you see a name that you like and wish to discuss price, please reach out to our sales team. How Do I Transfer a Premium Domain?   Transferring a premium domain involves a few steps, including unlocking the domain, obtaining an authorization code from the current registrar, and initiating the transfer with the new registrar. Many domain name marketplaces, including BrandBucket, offer assistance with the transfer process.