A new Microsoft sign-in screen phishing campaign is using genuine Microsoft login pages to bypass traditional phishing checks. Instead of directing users to a fake website, attackers trick them into approving a malicious app after they sign in.

Check Point researchers found that the campaign used convincing HR-themed Microsoft Teams lures. Once a victim grants app permissions, criminals can access Microsoft 365 services without stealing a password.

Fake Teams emails pressure employees to click

The attack begins with an email that appears to be a Teams notification from an HR department. It refers to payroll, compensation, benefits and overdue employee tasks to create a sense of urgency.

Recipients may believe they need to review an internal update quickly. However, the email link takes them to a genuine Microsoft sign-in page rather than a cloned website.

That detail makes the attack more difficult to detect. Users who check the address bar may see a legitimate Microsoft domain and assume the message is safe.

Real login pages hide the malicious consent request

Microsoft sign-in screen phishing is particularly effective because the authentication screen is real. The danger comes after the user signs in, when the campaign asks them to approve an unfamiliar application.

If the user grants consent, the malicious app can receive access to their email, Teams, SharePoint, OneDrive and calendar. Attackers do not need to capture the victim’s password to gain a foothold in the account.

This method is known as consent phishing. It abuses the legitimate OAuth permissions process instead of relying on a fake sign-in form or stolen credentials.

Check Point said the technique changes the usual phishing model. Every page the victim sees may be authentic, while the app requesting access has malicious intent.

Campaign targeted around 120 organisations

Researchers identified more than 200 unique phishing emails during a two-week period. The messages targeted users at roughly 120 organisations across multiple countries and industries.

Affected sectors included legal services and non-profit organisations, with targets concentrated in North America. Although the observed campaign is no longer active, Check Point warned that the broader technique is becoming more widespread.

Consent phishing is also becoming easier to launch. Researchers said it has moved from a specialised, manually built attack to a service that criminals can rent and use at scale.

That development could allow more attackers to use trusted cloud services and legitimate sign-in pages in their campaigns.

Internal-looking emails can still be dangerous

Employees should not trust a message simply because it appears to come from an internal address. Attackers can manipulate display names, sender details and sending domains to make phishing emails look legitimate.

In this campaign, the display name suggested Teams activity, while the message could appear to come from the recipient’s own email address. Such details can make an unexpected request appear more trustworthy.

Users should inspect links before clicking and compare the destination with the service named in the message. It is also worth checking whether several buttons in the email lead to the same destination.

When in doubt, employees should open Teams or another work application directly instead of using a link in an email.

How to reduce Microsoft sign-in screen phishing risk

Microsoft sign-in screen phishing cannot be stopped by teaching employees to spot fake login pages alone. Organisations also need to control app permissions and monitor new consent requests across their cloud environment.

Security teams should restrict who can approve third-party apps and require administrator approval for sensitive permissions. They should also review OAuth grants, investigate unfamiliar applications and remove malicious consent quickly.

Employees should carefully read any permission prompt before approving it. An app should not request access to email, files or calendars unless that access clearly matches its purpose.

Suspicious messages should be reported immediately. Early reporting helps security teams revoke app consent, identify affected accounts and block related campaign activity.


0 responses to “Attackers Use Real Microsoft Sign-In Screens in Phishing Campaign”