Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop
Tag:

devious

A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Gaming Gear

Hackers are looking to steal Microsoft logins using some devious new tricks – here’s how to stay safe

by admin August 25, 2025



  • A new phishing scheme successfully bypasses most security tools
  • It abuses ads and Microsoft’s Active Directory Federation Services tool
  • It is designed to steal login credentials, so users should take care

Cybercriminals have found a clever way to make phishing sites look like legitimate login pages, successfully stealing Microsoft credentials, experts have warned.

Cybersecurity researchers at Push Security recently published an in-depth report on how the scam works, outlining how the attackers created fake login pages that mimicked authentic Microsoft 365 sign-in screens.

Then, instead of sending victims directly to the site, which would probably get flagged by security solutions and quickly blocked, they used a Microsoft feature called Active Directory Federation Services (ADFS). Companies normally use it to connect their internal systems to Microsoft services.


You may like

How to stay safe

By setting up their own Microsoft account, and configuring it with ADFS, Microsoft’s service is tricked to redirect users to the phishing site, while making the link look legitimate because it starts with something like ‘outlook.office.com’.

Furthermore, the phishing link was not being distributed by email, but rather – malvertising. Victims were searching for “Office 265” which was presumably a typo, and were then taken to an Office login page. The ad also used a fake travel blog – bluegraintours[.]com – as a middle step to hide the attack.

The way the entire campaign was set up made it particularly dangerous. With the link looking like it was coming from Microsoft, and it successfully bypassing many security tools checking for bad links – its success rate was probably higher compared to “traditional” phishing.

Furthermore, since it doesn’t rely on email, the usual email filters couldn’t catch it. Finally, the landing page could even bypass multi-factor authentication (MFA), which made it even more dangerous.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

In order to prevent such scams from causing any real harm, IT teams should block ads, or at least monitor ad traffic, and watch for redirects from MIcrosoft login pages to unknown domains.

Finally, users should be careful when typing in search terms – a simple typo can lead to a fake ad that can result in device compromise and account takeover.

Via BleepingComputer

You might also like



Source link

August 25, 2025 0 comments
0 FacebookTwitterPinterestEmail

Categories

  • Crypto Trends (510)
  • Esports (372)
  • Game Reviews (322)
  • Game Updates (437)
  • GameFi Guides (500)
  • Gaming Gear (464)
  • NFT Gaming (509)
  • Product Reviews (451)

Recent Posts

  • Ethereum Treasury SharpLink Adds $252 Million in ETH to Holdings
  • This memecoin under $0.005 could outshine major cryptos
  • Bluesky exits Mississippi over age verification row
  • Burger King brings back Cini Minis nationwide after 13 years
  • Ripple Futures Open Interest Tops $1B at CME, With $3.70 Eyed Next

Recent Posts

  • Ethereum Treasury SharpLink Adds $252 Million in ETH to Holdings

    August 26, 2025
  • This memecoin under $0.005 could outshine major cryptos

    August 26, 2025
  • Bluesky exits Mississippi over age verification row

    August 26, 2025
  • Burger King brings back Cini Minis nationwide after 13 years

    August 26, 2025
  • Ripple Futures Open Interest Tops $1B at CME, With $3.70 Eyed Next

    August 26, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

About me

Welcome to Laughinghyena.io, your ultimate destination for the latest in blockchain gaming and gaming products. We’re passionate about the future of gaming, where decentralized technology empowers players to own, trade, and thrive in virtual worlds.

Recent Posts

  • Ethereum Treasury SharpLink Adds $252 Million in ETH to Holdings

    August 26, 2025
  • This memecoin under $0.005 could outshine major cryptos

    August 26, 2025

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

@2025 laughinghyena- All Right Reserved. Designed and Developed by Pro


Back To Top
Laughing Hyena
  • Home
  • Hyena Games
  • Esports
  • NFT Gaming
  • Crypto Trends
  • Game Reviews
  • Game Updates
  • GameFi Guides
  • Shop

Shopping Cart

Close

No products in the cart.

Close