Attackers are now exploiting trusted link wrapping services to steal Microsoft 365 credentials. The threat actors abused features in Proofpoint and Intermedia to mask phishing links.
How Attackers Exploited Trusted Links
From June through July 2025, attackers compromised email accounts with active link wrapping. They inserted malicious URLs, often shortened first. Then the wrapping service transformed them into trusted domains, tricking users into clicks.
When users clicked, the links routed through Proofpoint or Intermedia scanning servers before redirecting to fake Microsoft 365 login pages. Users perceived these links as safe due to the trusted domain.
Obfuscation Techniques Used
Attackers layered obfuscation steps:
- They shortened original malicious links using services like Bitly.
- They sent these from compromised accounts that automatically applied link wrapping.
- This created multi-tier redirect chains that bypass scanning delays.
- Cloudflare researchers call this technique “multi-tier redirect abuse.”
How Phishing Lures Worked
Emails pretended to be voicemail or Microsoft Teams notifications. Recipients clicked links to view a message or document. They landed on spoofed login pages, entering credentials without suspecting danger. The trusted wrapped domain increased the perceived legitimacy.
Why This Attack Is Effective
The method leverages inherent trust in enterprise security tools. Security filters often treat links wrapped by vendors as safe. Users receive fewer warnings and are more likely to click wrapped links.
By hijacking even protected accounts, attackers weaponized legitimate infrastructure to launch credential theft.
Mitigation Recommendations
Organizations should take these steps:
- Monitor for unusual email activity from protected accounts.
- Flag shortened links inside wrapped URLs.
- Block access to link wrapping domains if misuse is detected.
- Require multi-factor authentication for login.
- Train users to distrust even trusted-looking URLs.
Broader Implications
This campaign shows how cybercriminals weaponize security features. Link wrapping services intend to block known threats but can be co-opted successfully. Cloud providers, threat researchers, and CISOs must reassess trust models and detection logic.
Conclusion
Abusing Microsoft 365 link wrapping services allowed attackers to hide phishing links behind trusted domains. This clever method increased click-through probability and led to credential theft. Organizations should monitor link usage, update email security rules, and continue user training until defenses catch up.


0 responses to “Link Wrapping Abuse Steals Microsoft 365 Logins via Phishing”