Phishing Attacks Exploit Microsoft Visio Files and SharePoint
Threat actors are exploiting Microsoft Visio files and SharePoint to launch two-step phishing attacks, according to researchers at Perception Point.
“Perception Point’s security researchers have observed a dramatic increase in two-step phishing attacks leveraging .vsdx files – a file extension rarely used in phishing campaigns until now,” the researchers explain.
“These attacks represent a sophistication of two-step phishing tactics, targeting hundreds of organizations worldwide with a new layer of deception designed to evade detection and exploit user trust.”
The attacks begin with phishing emails that appear to be important business requests, such as purchase orders or proposals. The emails are sent from legitimate, compromised accounts, so they’re more likely to bypass security filters. The emails have Outlook attachments that lead to a Microsoft SharePoint page hosting a Visio (.vsdx) file.
“Inside the Visio file, attackers embed another URL behind a clickable Call-To-Action, in most cases we’ve observed it was a ‘View Document’ button,” the researchers write. “These files vary in appearance, with some even incorporating the breached user organization’s logos and branding to enhance credibility.
To access the embedded URL, victims are instructed to hold down the Ctrl key and click – a subtle yet highly effective action designed to evade email security scanners and automated detection tools. Asking for the Ctrl key press input relies on a simple interaction that a human user can perform, effectively bypassing automated systems that are not designed to replicate such behaviors.”
After clicking the link, the victim will be sent to a spoofed Microsoft 365 login page designed to steal their credentials.
New-school security awareness training can give your organization an essential layer of defense against phishing attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.
Perception Point has the story.
Free Phishing Security Test
Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.
- Immediately start your test for up to 100 users (no need to talk to anyone)
- Select from 20+ languages and customize the phishing test template based on your environment
- Choose the landing page your users see after they click
- Show users which red flags they missed, or a 404 page
- Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
- See how your organization compares to others in your industry
Here’s how it works:
PS: Don’t like to click on redirected buttons? Cut & Paste this link in your browser: https://info.knowbe4.com/phishing-security-test-partner?partnerid=001a000001lWEoJAAW