Legitimate SharePoint notifications used for phishing

Issue 2/3 2023 News & Events, Information Security

To hunt for corporate credentials, cybercriminals now hide phishing links in a file on a hijacked SharePoint server and distribute them using a native notification mechanism. Such emails are better at bypassing spam filters and seem more convincing, especially if the company uses this service.

Recently, Kaspersky experts observed more than 1600 malicious notifications with potential victims in Europe, North America, and other regions. Although the scale of the attacks is not massive yet, companies should be aware of the new scheme and mitigate risks in advance.

Spam filters are almost always capable of detecting phishing emails with a link in the body of the letter, so cybercriminals are constantly refining their tools to try bypassing security solutions. Now, they don’t just hide phishing links on a SharePoint server, as in previously known schemes, but they distribute it using legitimate SharePoint notifications.

This ploy using legitimate notifications lulls the vigilance of even tech-savvy employees. Notifications are sent on behalf of a real company’s services, and they do not raise doubts, especially if the company uses SharePoint as part of its everyday routine.

How phishing via SharePoint notifications works

An employee receives a standard SharePoint notification saying that someone has shared a OneNote file with them. This email is absolutely legitimate and can bypass the spam filter more easily than a phishing link hidden on a SharePoint server.

An employee follows the link, where the OneNote file mentioned opens, but the body of the note contains another ‘notification’ with a huge icon of a different type of file (for example, PDF) and a standard phishing link.

This phishing link leads to a phishing website that mimics the Microsoft OneDrive login page. Cybercriminals use it to steal the credentials for various email accounts, such as Yahoo!, AOL, Outlook, Office 365, and others.

How companies can mitigate risks against this type of phishing

Although such phishing letters are convincing, they are distinguishable by an array of red flags that can be explained to employees.

"To begin with, the file is unknown as well as the sender. Colleagues don’t normally share documents without an intro. There are more red flags: a link to the OneNote file in the notification and PDF-file appears on the server out of the blue. Furthermore, the download link leads to a third-party site, and the web address has nothing to do with the victim's organisation or SharePoint server. The phishing site mimics login page for OneDrive, which is another Microsoft service that is not related to SharePoint. To stay safe, it is necessary to use caution with all suspicious emails and watch out for such inconsistencies," explains Roman Dedenok, Spam Analysis Expert at Kaspersky.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Hytera supports communication upgrade for Joburg
News & Events Infrastructure Government and Parastatal (Industry)
By equipping Johannesburg’s metro police and emergency services with multimode radios which integrate TETRA and LTE networks, Hytera is bridging coverage gaps and improving response times across the city.

Read more...
The global generative AI market surpassed $130 billion in 2024
News & Events AI & Data Analytics
According to a new research report from the IoT analyst firm, Berg Insight, the Generative AI (GenAI) market grew substantially in 2024, experiencing triple-digit growth rates in all three major segments: GenAI hardware, foundation models, and development platforms.

Read more...
Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
ProtecLink 2025: Ithegi Electronics supports a safer, smarter security ecosystem
News & Events
If you are a security buyer, operations lead, or technology partner, do not miss ProtecLink 2025, to be held in Polokwane on 16 September 2025, at the Polokwane Royal Hotel.

Read more...
IZI Group acquires G4S Cash Solutions South Africa
News & Events
IZI Africa, a sister company within the IZI Group, has acquired G4S Cash Solutions (SA) following the receipt of all necessary regulatory approvals. This transaction marks a significant consolidation in the South African cash handling industry.

Read more...
Secutel maintains ISO certifications
News & Events Fire & Safety
Secutel Technologies has successfully recertified all four of its ISO standards, a reflection of its continued commitment to excellence, client trust, and operational integrity.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
SABRIC appoints Andre Wentzel as interim CEO
News & Events Financial (Industry) Associations
The South African Banking Risk Information Centre (SABRIC) has announced the appointment of Andre Wentzel as interim chief executive officer, effective immediately.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Paxton cuts emissions by over a third
Paxton News & Events
Paxton has announced a significant reduction in its carbon footprint, cutting emissions by 961 tonnes of CO2e in its 2023 second reporting year.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.