This devious two-step phishing campaign uses Microsoft tools to bypass email security


- Two-step phishing evades security with user-triggered actions
- Fake Microsoft portals harvest sensitive login credentials fast
- Advanced threat detection is key to fighting phishing
A two-step phishing attack is leveraging Microsoft Visio files (.vsdx) and SharePoint, marking a new chapter in cyber deception, experts have warned.
Perception Point’s security researchers reported a dramatic increase in attacks leveraging .vsdx files.
These files, which were rarely used in phishing campaigns until now, are used as a delivery mechanism, with victims being redirected to phishing pages mimicking Microsoft 365 login portals, designed to steal user credentials.
Phishing exploits trusted platforms
Two-step phishing attacks layer malicious actions to evade detection. Instead of delivering harmful content directly, these campaigns rely on trusted platforms like Microsoft SharePoint to host seemingly legitimate files.
The attackers embed URLs within Microsoft Visio files that direct victims to malicious websites when clicked. This layered approach makes detection by traditional email security systems more challenging.
Microsoft Visio, a widely used tool for creating professional diagrams, has become a new vector for phishing. Attackers use compromised accounts to send emails containing Visio files appear to originate from trusted sources, often mimicking urgent business communications, like proposals or purchase orders to prompt immediate action.
As the attackers use stolen accounts, these emails often pass authentication checks and are more likely to bypass recipient security systems. In some instances, the attackers include .eml files within the emails, further embedding malicious URLs that lead to SharePoint-hosted files.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The attackers embed a clickable button inside the Visio file, typically labelled “View Document.” To access the malicious URL, victims are instructed to hold down the Ctrl key and click the button. This interaction, requiring a manual user action, bypasses automated security systems that cannot replicate such behaviors.
To mitigate risks posed by such sophisticated phishing campaigns, Perception Point recommends organizations adopt advanced threat detection solutions, including dynamic URL analysis to identify malicious links, object detection models to flag suspicious files, and authentication mechanisms to minimize the impact of breached accounts.
You may also like
Two-step phishing evades security with user-triggered actions Fake Microsoft portals harvest sensitive login credentials fast Advanced threat detection is key to fighting phishing A two-step phishing attack is leveraging Microsoft Visio files (.vsdx) and SharePoint, marking a new chapter in cyber deception, experts have warned. Perception Point’s security researchers reported…
Recent Posts
- A GPU or a CPU with 4TB HBM-class memory? Nope, you’re not dreaming, Sandisk is working on such a monstrous product
- The Space Force shares a photo of Earth taken by the X-37B space plane
- Elon Musk claims federal employees have 48 hours to explain recent work or resign
- xAI could sign a $5 billion deal with Dell for thousands of servers with Nvidia’s GB200 Blackwell AI GPU accelerators
- Race to 100TB HDD heats up as Seagate pulls rug under Western Digital, Toshiba feet by acquiring HAMR-specialist
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010