News: 1594246065

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft sues coronavirus phishing spammers to seize their domains amid web app attacks against Office 354.5

(2020/07/08)


Microsoft has taken legal action to seize web domains being used to launch coronavirus-themed phishing attacks.

The Windows giant obtained an order from US courts allowing it to seize domains being used for phishing, having first spotted the miscreants doing their thing in December 2019.

“Microsoft’s Digital Crimes Unit (DCU) first observed these criminals in December 2019, when they deployed a sophisticated, new phishing scheme designed to compromise Microsoft customer accounts,” said the mega-corp in a [1]blog post this week.

Having KO’d them back then through unspecified “technical means to block the criminals’ activity and disable the malicious application used in the attack,” Redmond’s people observed them setting up again to try business email compromise attacks with a coronavirus theme.

Hundreds of forgotten corners of mega-corp websites fall into the hands of spammers and malware slingers [2]READ MORE

The phishing lures included bait text such as “COVID-19 Bonus,” said Microsoft. Upon clicking links provided in the phishing emails, victims were sent to a web app demanding extra permissions. Once armed with this elevated access, the web app would then access the victims' Office 365 accounts.

“This scheme enabled unauthorized access without explicitly requiring the victims to directly give up their login credentials at a fake website or similar interface, as they would in a more traditional phishing campaign,” said Microsoft.

Redmond has not shied away from legal action over the years, the most high-profile sueball being its ongoing case against the American government to [3]stop agents helping themselves to non-US customer data stored on non-US-based Microsoft servers. It’s also suing Uncle Sam for [4]the right to tell customers when American spies are trawling through data stored on Microsoft services.

Further back in time, MICROS~1 has [5]sued dodgy resellers , operators of [6]alleged monopolies (stop laughing at the back), [7]Google and, at the dawn of time, [8]British Hotmail spammers. ®

Get our [9]Tech Resources



[1] https://blogs.microsoft.com/on-the-issues/2020/07/07/digital-crimes-unit-covid-19-cybercrime/

[2] https://www.theregister.com/2020/07/07/microsoft_azure_takeovers/

[3] https://www.theregister.com/2018/04/17/supreme_court_punts_email_seizure_decision_into_the_long_grass/

[4] https://www.theregister.com/2019/09/27/microsoft_gag_orders/

[5] https://www.theregister.com/2015/09/21/microsoft_sues_recycler_office_2010_copyright/

[6] https://www.theregister.com/2015/08/21/microsoft_sues_interdigital_over_mobile_patents/

[7] https://www.theregister.com/2012/10/12/microsoft_suing_google/

[8] https://www.theregister.com/2006/09/13/ms_sues_british_spammer/

[9] https://whitepapers.theregister.com/

That much downtime?

David 132

Article headline at the time of writing this: amid web app attacks against Office 265

Now, I know they've had a lot of downtime, and I've variously heard it referred to as Office 364, Office 360 and so on, but a whole 100 days? At that point, probably safer to host your data on a stack of knockoff Chinese 5.25" floppy disks held onto your fridge with a magnet.

Yeah yeah, I should use the "Send a correction" link, but this was too funny not to call out!

Re: That much downtime?

Steve Foster

Given the frequency with which all the cloud services like to go TITSUP, I'd say 265 is probably about right.

Re: That much downtime?

diodesign

Just assume any value after Office is correct. I'd ask our tech team to make an automatic randomzier for the headline but they seem rather busy on actual functionality.

PS: corrections@theregister.com works well for any typo :p

C.

Microsoft’s Digital Crimes Unit (DCU)

Anonymous Coward

Is this a real thing? Can we watch it on Netflix?

Something about motes and beams...

Steve Foster

...it'd be nice if they could stop the silly DoS crap originating from some of their *.outbound.protection.outlook.com servers.

Stuff like this, where they just connect and then drop the connection over and over:

07/07/2020 13:04:41 - ( 2911) EHLO GBR01-LO2-obe.outbound.protection.outlook.com

07/07/2020 13:04:41 - ( 2911) 250-Welcome, mail-lo2gbr01lp2055.outbound.protection.outlook.com [104.47.21.55], pleased to meet you

07/07/2020 13:04:41 - ( 2911) 250-AUTH=LOGIN

07/07/2020 13:04:41 - ( 2911) 250-AUTH LOGIN

07/07/2020 13:04:41 - ( 2911) 250-SIZE 20971520

07/07/2020 13:04:41 - ( 2911) 250-ETRN

07/07/2020 13:04:41 - ( 2911) 250 HELP

07/07/2020 13:04:41 - ( 2911) Error: [10054] Connection reset by peer

Re: Something about motes and beams...

DJV

Are those dates in American MM/DD/YYYY format or UK DD/MM/YYYY format?

Enquiring minds etc....

Re: Something about motes and beams...

joesomeone

Maybe the sender's send connector enforces TLS.

Given the DNS PTR naming convention, it looks like this might be part of their low-quality/SRS IP pool. At least that's what I gather from reading the tea leaves.

But it doesn't sound like you're missing anything important, nevertheless. :)

Don't worry, Borkzilla

Pascal Monett

“ This scheme enabled unauthorized access without explicitly requiring the victims to directly give up their login credentials at a fake website or similar interface "

No problem here, I don't have a Borkzilla account, so there's nothing to phish.

You see, I have an innate distrust of anything that tries to tie me into its universe. That's why I don't have a YouTube account, or a FaceBook account, or an Office x65 account. I fail to see why I should give you all the details of my comings and goings on the Internet, since it's none of your clucking business.

He's the kind of guy, that, well, if you were ever in a jam he'd
be there... with two slices of bread and some chunky peanut butter.