Microsoft Impersonated to Deliver COVID-19 Phishing Attack

February 26, 2021

In this attack, attackers impersonate a company's Human Resources department and send a COVID-19 scan via a lookalike Microsoft Office 365 email.

Summary of Attack Target

  • Platform: Office 365
  • Victims: Employees
  • Payload: Malicious Link
  • Technique: Impersonation

Microsoft Impersonated in Phishing Attack

The original message to the recipient appears to originate from the company’s internal human resources email address. The email looks to be a regular Microsoft O365 notification, notifying the recipient that a document has been shared with them, but the link embedded in the message leads to a phishing site.

The impersonated O365 email contains a document that poses as a PDF regarding a "Covid-19 Report". The email itself includes the Microsoft logo in the footer, increasing the visual legitimacy of this message. The email also states that the file is secure and has been scanned for viruses, which may dupe the recipient into following the link.

When clicking the link in the email, the recipient is presented with a page that appears nearly identical to that of the Microsoft login page and prompted to input their credentials.

Although this appears to be the legitimate Microsoft login page, the URL '' clearly has no relation to Microsoft. If the recipient were to input their login information to "view the document" that they just received, their credentials would be compromised by the attacker.

Why It Bypassed Existing Security Infrastructure

In this attack, the attackers spoof an internal email domain, which can be challenging to catch, especially if expertly done. The attackers also utilized a trusted brand—Microsoft—to deliver their phishing link, utilizing a very convincing email template and login screen. And because the Microsoft email leads to a Microsoft site, the attack relies on users simply inputting their password in order to see the COVID-19 report.

Abnormal Security prevented this attack by analyzing various attack signals that flagged this email as malicious. Key indicators were the impersonation of a known brand, the presence of a suspicious link, and a mismatch between the sender domain and the display name.

These signals, combined with a dramatic increase in COVID-19 phishing attacks, work together to inform us that this message is malicious. As a result, this message is blocked from inboxes before it can lead to compromised employee accounts.

Discover how Abnormal Security can stop brand impersonations and credential phishing emails for your organizations. Get started by requesting a short demo.


Prevent the Attacks That Matter Most

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Demo 2x 1

See the Abnormal Solution to the Email Security Problem

Protect your organization from the attacks that matter most with Abnormal Integrated Cloud Email Security.

Related Posts

B 09 29 22 CISO Cybersecurity Awareness Month
October is here, which means Cybersecurity Awareness Month is officially in full swing! These five tips can help security leaders take full advantage of the month.
Read More
B Email Security Challenges Blog 09 26 22
Understanding common email security challenges caused by your legacy technology will help you determine the best solution to improve your security posture.
Read More
B 5 Crucial Tips
Retailers are a popular target for threat actors due to their wealth of customer data and availability of funds. Here are 5 cybersecurity tips to help retailers reduce their risk of attack.
Read More
B 3 Essential Elements
Legacy approaches to managing unwanted mail are neither practical nor scalable. Learn the 3 essential elements of modern, effective graymail management.
Read More
B Back to School
Discover how threat group Chiffon Herring leverages impersonation and spoofed email addresses to divert paychecks to mule accounts.
Read More
B 09 06 22 Rearchitecting a System Blog
We recently shared a look at how the Abnormal engineering team overhauled our Unwanted Mail service architecture to accommodate our rapid growth. Today, we’re diving into how the team migrated traffic to the new architecture—with zero downtime.
Read More
B Industry Leading CIS Os
Stay up to date on the latest cybersecurity trends, industry news, and best practices by following these 12 innovative and influential thought leaders on social media.
Read More
B Podcast Engineering 11 08 24 22
In episode 11 of Abnormal Engineering Stories, David Hagar, Director of Engineering and Abnormal Head of UK Engineering, continues his conversation with Zehan Wang, co-founder of Magic Pony.
Read More
B Overhauled Architecture Blog 08 29 22
As our customer base has expanded, so has the volume of emails our system processes. Here’s how we overcame scaling challenges with one service in particular.
Read More