Microsoft Sway abused in massive QR code phishing campaign

Teilen:

​A massive QR code phishing campaign abused Microsoft Sway, a cloud-based tool for creating online presentations, to host landing pages to trick Microsoft 365 users into handing over their credentials.

The attacks were spotted by Netskope Threat Labs in July 2024 after detecting a dramatic 2,000-fold increase in attacks exploiting Microsoft Sway to host phishing pages that steal Microsoft 365 credentials. This surge sharply contrasts the minimal activity reported during the year’s first half, showing the large scale of this campaign.

They primarily targeted users in Asia and North America, with the technology, manufacturing, and finance sectors being the most sought-after targets.

The emails redirected potential victims to phishing landing pages hosted on the sway.cloud.microsoft domain, pages that encouraged the targets to scan QR codes that would send them to other malicious websites.

Attackers often encourage victims to scan QR codes using their mobile devices, which typically come with weaker security measures, thus increasing the chances of bypassing security controls and allowing them to access phishing sites without restrictions.

“Since the URL is embedded inside an image, email scanners that can only scan text-based content can get bypassed. Additionally, when a user gets sent a QR code, they may use another device, such as their mobile phone, to scan the code,” the security researchers explained.

“Since the security measures implemented on mobile devices, particularly personal cell phones, are typically not as stringent as laptops and desktops, victims are then often more vulnerable to abuse.”

The attackers employed several tactics to further boost their campaign’s effectiveness, like transparent phishing, where they stole the credentials and multi-factor authentication codes and used them to sign the victims into their Microsoft accounts while showing them the legitimate login page.

They also used Cloudflare Turnstile, a tool intended to protect websites from bots, to hide their landing pages’ phishing content from static scanners, helping to maintain the phishing domain’s good reputation and avoid getting blocked by web filtering services like Google Safe Browsing.

Microsoft Sway was also abused in the PerSwaysion phishing campaign, which targeted Office 365 login credentials five years ago using a phishing kit offered in a malware-as-a-service (MaaS) operation.

As Group-IB security researchers revealed at the time, those attacks tricked at least 156 high-ranking individuals at small and medium financial services companies, law firms, and real estate groups.

Group-IB said that over 20 of all harvested Office 365 accounts belong to executives, presidents, and managing directors at organizations in the U.S., Canada, Germany, the U.K., the Netherlands, Hong Kong, and Singapore.

Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
9:18 am, Mai 9, 2025
Wetter-Symbol 10°C
L: 9° | H: 11°
broken clouds
Luftfeuchtigkeit: 79 %
Druck: 1020 mb
Wind: 6 mph E
Windböe: 9 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:17 am
Sonnenuntergang: 8:35 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
9° | 11°°C 0 mm 0% 12 mph 79 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 12 mph 86 % 1021 mb 0 mm/h
So. Mai 11 10:00 pm
Wetter-Symbol
11° | 23°°C 0.94 mm 94% 12 mph 86 % 1015 mb 0 mm/h
Mo. Mai 12 10:00 pm
Wetter-Symbol
12° | 21°°C 0.97 mm 97% 11 mph 95 % 1016 mb 0 mm/h
Di. Mai 13 10:00 pm
Wetter-Symbol
13° | 21°°C 0.46 mm 46% 11 mph 77 % 1022 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
10° | 12°°C 0 mm 0% 8 mph 79 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
12° | 16°°C 0 mm 0% 12 mph 66 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 11 mph 48 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
15° | 15°°C 0 mm 0% 9 mph 40 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 8 mph 63 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 6 mph 74 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 4 mph 86 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 79 % 1020 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,209.94
4.14%
Ethereum(ETH)
€2,115.92
23.27%
Fesseln(USDT)
€0.89
0.01%
XRP(XRP)
€2.09
6.73%
Solana(SOL)
€147.89
9.13%
USDC(USDC)
€0.89
-0.01%
Dogecoin(DOGE)
€0.184679
13.89%
Shiba Inu(SHIB)
€0.000013
10.88%
Pepe(PEPE)
€0.000011
35.02%
Peanut das Eichhörnchen(PNUT)
€0.246628
64.52%
Nach oben scrollen