chat
expand_more

Compromised Account Used to Launch Internal Phishing Attack

Compromised accounts are commonly used by cybercriminals to send additional attacks because they appear to originate from a trustworthy source—typically a known partner or customer, or a known coworker within the organization. In this attack, the account was first...
August 9, 2020

Compromised accounts are commonly used by cybercriminals to send additional attacks because they appear to originate from a trustworthy source—typically a known partner or customer, or a known coworker within the organization. In this attack, the account was first compromised, and then attackers used it to launch internal phishing attacks to gain access to additional accounts.

Summary of Attack Target

  • Platform: Office 365
  • Email Security: Proofpoint
  • Victims: Internal Employees
  • Payload: Malicious Link
  • Technique: Compromised Internal Account

Overview of the Internal Phishing Atack

In this attack, the email itself is simple and masquerades as an encrypted message notification related to a OneDrive for Business file. It appears to come from an internal account and is sent to a known coworker, asking them to open the message.

Internal phishing attack email
The email sent in an internal phishing attack

If the recipient clicks on the link, it takes them to a PDF hosted on a Russian domain, which guides victims to click on another link to view and download the supposed file. After clicking the second link, the victims are taken to a phishing page.

Internal phishing attack PDF
The PDF link that leads to a phishing page

The phishing page asks the victim to enter their Microsoft credentials in order to access the document. Should victims fall for this attack, they risk further compromise within their company as the attacker gains access to more OneDrive and Microsoft Office accounts, from which they can steal valuable and sensitive information, hijack existing conversations, or create new attacks on other employees.

Why Compromised Accounts are Effective for Phishing

By utilizing a compromised internal account, the attacker is able to bypass any external email filtering set in place by the company, as most traditional infrastructure does not view internal-to-internal, or east-west traffic. In addition, it is easier to deceive recipients of this email, as the email appears to be coming from a coworker.

In addition, the link in the email is hidden in the text of the company’s name, and the link hosted on the Russian domain is concealed in the text that says “VIEW ONLINE / DOWNLOAD”. After clicking the links, victims are taken to a phishing page tailored specifically to their company.

Abnormal Security detecting internal phishing
Abnormal Security detecting an internal phishing attempt

Abnormal stopped this attack due to a variety of malicious signals. Most notably, the attacker sent the original email from an IP located in the United Kingdom, which is suspicious because this sender never sends from the UK, and the recipient rarely receives emails from there either. Combined with the BCC recipient pattern and the suspicious link, it's clear that this account has been compromised and is now being used to attack the organization.

To learn how Abnormal can detect account takeovers within your organization, request a demo today.

Compromised Account Used to Launch Internal Phishing Attack

See Abnormal in Action

Get a Demo

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

Get AI Protection for Your Human Interactions

Protect your organization from socially-engineered email attacks that target human behavior.
Request a Demo
Request a Demo

Related Posts

B Proofpoint Customer Story Blog 8
A Fortune 500 transportation and logistics leader blocked more than 6,700 attacks missed by Proofpoint and reclaimed 350 SOC hours per month by adding Abnormal to its security stack.
Read More
B Gartner MQ 2024 Announcement Blog
Abnormal Security was named a Leader in the 2024 Gartner Magic Quadrant for Email Security Platforms and positioned furthest for Completeness of Vision.
Read More
B Gift Card Scams Tricker to Spot Blog
Learn why gift card scams are becoming more difficult to identify, how cybercriminals evolve their tactics, and strategies to protect your organization.
Read More
B Offensive AI 12 16 24
Learn how AI is used in cybersecurity, what defensive AI vs. offensive AI means, and how to use defensive AI to combat offensive AI.
Read More
B Proofpoint Customer Story Blog 7
See how Abnormal's AI helped a Fortune 500 insurance provider detect 27,847 threats missed by Proofpoint and save 6,600+ hours in employee productivity.
Read More
B Cyberattack Forecast Emerging Threats Blog
Uncover the latest email threats and strategies to strengthen your cybersecurity and prepare for 2025.
Read More