Phishing

Phishers Abuse SharePoint in New Campaign Targeting Energy Sector

Threat actors are leveraging the file-sharing service for payload delivery in AitM phishing and BEC attacks.

Threat actors have been abusing SharePoint for payload delivery in a new phishing campaign targeting energy organizations, Microsoft warns.

One multi‑stage attack analyzed by Microsoft started with adversary‑in‑the‑middle (AitM) phishing, where the victim received an email from the compromised account of a trusted organization.

The message featured a document‑sharing workflow theme and included a SharePoint URL that directed the victim to a landing page prompting them for their Microsoft credentials.

Next, the attackers set up for business email compromise (BEC), accessing the compromised inbox and creating rules to mark all messages as read and delete incoming emails. They then sent over 600 phishing emails to the victim’s contacts, with another phishing URL.

“The recipients were identified based on the recent email threads in the compromised user’s inbox,” Microsoft explains.

The attackers monitored the compromised account, deleting undelivered and out-of-office responses, as well as messages from recipients who questioned the authenticity of the phishing emails.

Advertisement. Scroll to continue reading.

“The emails and responses were then deleted from the mailbox. These techniques are common in any BEC attacks and are intended to keep the victim unaware of the attacker’s operations, thus helping in persistence,” Microsoft explains.

The attackers mounted another AitM attack against the recipients from within the organization who clicked on the phishing URL, the company notes.

To protect themselves from such attacks, organizations are advised to implement multi-factor authentication (MFA) and enable conditional access policies in Microsoft Entra.

However, because AitM attacks result in the compromise of sign-in sessions, remediation requires not only resetting the compromised users’ passwords but also revoking the sessions and verifying that MFA has not been tampered with.

“While AiTM phishing attempts to circumvent MFA, implementation of MFA remains an essential pillar in identity security and highly effective at stopping a wide variety of threats. MFA is the reason that threat actors developed the AiTM session cookie theft technique in the first place,” Microsoft notes.

Implementing continuous access evaluation, passwordless sign-in, enabling networking protection in endpoint security solutions, implementing security solutions on mobile devices, and using browsers that automatically identify and block malicious websites also help mitigate the risk associated with these attacks.

Related: LastPass Users Targeted With Backup-Themed Phishing Emails

Related: FBI: North Korean Spear-Phishing Attacks Use Malicious QR Codes

Related: Complex Routing, Misconfigurations Exploited for Domain Spoofing in Phishing Attacks

Related: AI Is Supercharging Phishing: Here’s How to Fight Back

Related Content

Phishing

The platform used more than 9,000 phishing sites, stealing nearly 4 million credit cards and causing roughly $1.9 billion in losses.

Vulnerabilities

The company warned about zero-day attacks exploiting the Exchange Server vulnerability CVE-2026-42897 on May 14. 

Vulnerabilities

Three of the vulnerabilities fixed with the latest Patch Tuesday updates were publicly disclosed before Microsoft addressed them.

Vulnerabilities

Microsoft responds to backlash over its threats of legal action against researchers who publicly disclose zero-day vulnerabilities.

Mobile & Wireless

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations.

Vulnerabilities

The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.

Malware & Threats

 Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.

Artificial Intelligence

Microsoft’s MDASH discovered 16 of the Patch Tuesday vulnerabilities, and Palo Alto used Mythos to find dozens of flaws. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version