Microsoft Impersonated to Deliver COVID-19 Phishing Attack

February 26, 2021

In this attack, attackers impersonate a company's Human Resources department and send a COVID-19 scan via a lookalike Microsoft Office 365 email.

Summary of Attack Target

  • Platform: Office 365
  • Victims: Employees
  • Payload: Malicious Link
  • Technique: Impersonation

Microsoft Impersonated in Phishing Attack

The original message to the recipient appears to originate from the company’s internal human resources email address. The email looks to be a regular Microsoft O365 notification, notifying the recipient that a document has been shared with them, but the link embedded in the message leads to a phishing site.

The impersonated O365 email contains a document that poses as a PDF regarding a "Covid-19 Report". The email itself includes the Microsoft logo in the footer, increasing the visual legitimacy of this message. The email also states that the file is secure and has been scanned for viruses, which may dupe the recipient into following the link.

When clicking the link in the email, the recipient is presented with a page that appears nearly identical to that of the Microsoft login page and prompted to input their credentials.

Although this appears to be the legitimate Microsoft login page, the URL '' clearly has no relation to Microsoft. If the recipient were to input their login information to "view the document" that they just received, their credentials would be compromised by the attacker.

Why It Bypassed Existing Security Infrastructure

In this attack, the attackers spoof an internal email domain, which can be challenging to catch, especially if expertly done. The attackers also utilized a trusted brand—Microsoft—to deliver their phishing link, utilizing a very convincing email template and login screen. And because the Microsoft email leads to a Microsoft site, the attack relies on users simply inputting their password in order to see the COVID-19 report.

Abnormal Security prevented this attack by analyzing various attack signals that flagged this email as malicious. Key indicators were the impersonation of a known brand, the presence of a suspicious link, and a mismatch between the sender domain and the display name.

These signals, combined with a dramatic increase in COVID-19 phishing attacks, work together to inform us that this message is malicious. As a result, this message is blocked from inboxes before it can lead to compromised employee accounts.

Discover how Abnormal Security can stop brand impersonations and credential phishing emails for your organizations. Get started by requesting a short demo.


Prevent the Attacks That Matter Most

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Demo 2x 1

See the Abnormal Solution to the Email Security Problem

Protect your organization from the attacks that matter most with Abnormal Integrated Cloud Email Security.

Related Posts

B 05 13 22 Spring Product Release
This quarter, the team at Abnormal launched new features to improve lateral attack detection, role-based access control (RBAC), and explainable AI. Take a deep dive into all of the latest product enhancements.
Read More
B 05 11 22 Champion Finalist
Abnormal has been selected as a Security Customer Champion finalist in the Microsoft Security Excellence Awards! Here’s a look at why.
Read More
Blog series c cover
When we raised our Series B funding 18 months ago, I promised our customers greater value, more capabilities, and better customer support. We’ve delivered on each of those promises and as we receive an even larger investment, I’m excited about how we can continue to further deliver on each of them.
Read More
B 05 09 22 Partner Community
It’s an honor to be named one of CRN’s 2022 Women of the Channel. Here’s why I appreciate the award and what I love about being a Channel Account Manager at Abnormal.
Read More
B 05 05 22 Fast Facts
Watch this short video to learn current trends and key issues in cloud email security, including how to protect your organization against modern threats.
Read More
B 05 03 22
Like all threats in the cyber threat landscape, ransomware will continue to evolve over time. This post builds on our prior research and looks at the changes we observed in the ransomware threat landscape in the first quarter of 2022.
Read More
B 04 28 22 8 Key Differences
At Abnormal, we pride ourselves on our excellent machine learning engineering team. Here are some patterns we use to distinguish between effective and ineffective ML engineers.
Read More
B 04 26 22 Webinar Re Replacing Your SEG
Learn how Microsoft 365 and Abnormal work together to provide comprehensive defense-in-depth protection in part two of our webinar recap.
Read More
Blog mitigate threats cover
Learn about the most common socially-engineered attacks and why these tactics are still so successful—despite a growing awareness from employees.
Read More
B Podcast Engineering8
In episode 8 of Abnormal Engineering Stories, Kevin interviews Saminda Wijegunawardena, an engineering leader who is no stranger to fast-growing enterprise startups.
Read More
B 04 04 22 Webinar Recap Krebs
High-impact emails are on the rise and secure email gateways (SEGs) don’t have the functionality to mitigate them. Learn how your SEG is letting you down.
Read More
B 04 19 22 Facebook Phishing
While phishing emails have long been a popular way to steal Facebook login credentials, we’ve recently seen an increase in more sophisticated phishing attacks.
Read More