Close Menu
  • Business
    • Market Place
  • Devices & Gadgets
    • Buyers Guide
    • Trending
    • Social
  • Mobile & Telecoms
    • Broadband
  • Innovations
    • APPS
    • Start-ups
    • Software
    • AI ( artificial intelligence)
    • Auto-Tech
  • Health
    • Security
  • State
    • NCC
    • NiRA and .ng
    • NITDA
  • i-Sports
    • i-tertainment/Gaming
    • I-TV/Podcast
  • Reviews
    • Opinion
    • Special Report
    • Editorial and Analysis
  • Others
    • Events
    • Archive
    • Interviews
Facebook X (Twitter) Instagram
Latest
  • TD Africa Onboards Zinox Technologies, Expanding Its Basket of Global Brands
  • Highlights from the 10th Nigeria Innovation Summit
  • First Bank unveils its latest Digital Xperience Centre in Abuja
  • Yemisi Shyllon Museum of Art Presents Second Edition of Collecting Now Exhibition
  • E1 Lagos GP: Lagos Trends Worldwide After Hosting Africa’s Maiden Water Racing Event
  • TD Africa and IBM Spotlight Digital Innovation at GITEX Nigeria 2025
  • FBNQuest Merchant Bank bags “Great Place to Work” Certification
  • NCC in history – avoiding the psychic prison syndrome
Facebook X (Twitter) Instagram YouTube LinkedIn
IT NEWS NIGERIAIT NEWS NIGERIA
Subscribe Now
  • Business
    • Market Place
  • Devices & Gadgets
    • Buyers Guide
    • Trending
    • Social
  • Mobile & Telecoms
    • Broadband
  • Innovations
    • APPS
    • Start-ups
    • Software
    • AI ( artificial intelligence)
    • Auto-Tech
  • Health
    • Security
  • State
    • NCC
    • NiRA and .ng
    • NITDA
  • i-Sports
    • i-tertainment/Gaming
    • I-TV/Podcast
  • Reviews
    • Opinion
    • Special Report
    • Editorial and Analysis
  • Others
    • Events
    • Archive
    • Interviews
IT NEWS NIGERIAIT NEWS NIGERIA
Home»Security»Office 365: New phishing attack tries to steal credentials via Box
Security

Office 365: New phishing attack tries to steal credentials via Box

ITNEWSNIGERIABy ITNEWSNIGERIAAugust 27, 2020No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
office 365 attack
Share
Facebook Twitter LinkedIn Pinterest Email

Office 365 new phishing attack: Researchers at cloud security platform Armorblox have uncovered a phishing attack that seeks to steal Office 365 login credentials

Advertisement

IT News Nigeria:

So far, so predictable. The clever twist here though is that the initial page victims are taken to via the email link is hosted on cloud file sharing service Box, followed by a credential phishing page that resembles the Office 365 login portal.

The sender name and domain used belong to a legitimate company and this together with the use of Box helps the attack to evade detection and get through to people’s inboxes. The emails are also constructed to encourage people to click, with a simple call to action — Click here to pick up your documents — and footer text that informs readers that the email link will only be active for a limited time, giving a sense of urgency.

Read also:

Email attacks: Criminals bypass multi-factor authentication to hijack email accounts

‘Argentina Is Doing It’: NITDA Alerts Nigerians on Harmful Fake Messages

“The first page in this attack flow was hosted on Box, leveraging the reputation of the Box domain to get past any filters used to block known bad domains,” writes Arjun Sambamoorthy, co-founder and head of engineering at Armorblox on the company’s blog.

cyber attack
Cyber Awareness Forum to mark World Safer Internet Day 2018 in Lagos

“The page looked like it was hosting a document that was shared over OneDrive, with plenty of Microsoft branding used to lull users into a false sense of security. The document displays ‘Secured by OneDrive’ on the top left corner, ‘OneDrive for Business’ emblazoned on the center, and ‘Powered by Office 365’ on the bottom left corner.”

If users clicked the ‘Access Document’ link on the Box page, they were redirected to a page resembling the Office 365 login portal which would scoop up their credentials.

You can read more about the attack, including how it was detected on the Armorblox blog. – Culled from BETANEWS

Image Credit: Maksim Kabakou / Shutterstock

Post Views: 337
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleZenith Bank GMD Urges New Intensive Efforts to Expand Non-Oil Exports
Next Article 5G: Why Group makes new case for deployment 10 months after trial in Nigeria
ITNEWSNIGERIA

Related Posts

3 Mins Read

Sophos XDR Excels in MITRE ATT&CK Evaluations: Enterprise

December 17, 2024
3 Mins Read

Teresa Anania Joins Sophos as Chief Customer Officer

July 23, 2024
4 Mins Read

Financial Education: 8 Important Steps To Secure Your PalmPay Account

June 25, 2024
5 Mins Read

Trend Micro blocked 18 million email threats, 4million  malicious mobile apps targeted at Nigerian businesses

May 25, 2024
Leave A Reply Cancel Reply

About Us
IT NEWS NIGERIA (www.itnewsnigeria.ng) is an on-line platform aimed at enriching Nigeria and Africa content in the cyberspace.

We believe the future is online.
Popular Updates

Design Bootcamps vs Self-Taught, A product designer’s perspective

March 22, 2024

How to get N100,000 loan @3% at Zenith Bank and other services

November 12, 2020

Interview: From Start-ups to Big Brands: Growth Marketing Strategies that work by Oluwasekemi Akinbo

May 18, 2023

Subscribe to Updates

Get the latest tech news & updates from IT NEWS NIGERIA

Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn
  • About Us
  • Privacy Policy
  • Terms of Service
  • Advertise With Us
  • Contact Us
© 2025 IT NEWS NIGERIA.

Type above and press Enter to search. Press Esc to cancel.

Signup to our Newsletter