Islamabad (GNP): Kaspersky researchers have uncovered a scam campaign in which criminals send emails carrying genuine Microsoft links that lead victims to fake websites or to malware downloads. Between August 1 and September 18, Kaspersky products blocked more than 31,000 emails containing such links.
Earlier this year, Kaspersky reported a phishing campaign that exploited Microsoft’s authentication mechanism. The company has now described how criminals are abusing the same technology with a different lure. The emails pose as official Microsoft messages and push recipients to click a link, either to keep their service credentials up to date or to sign electronic documents.
To set up the redirect, the attackers open a Microsoft account, sign in to the Microsoft Entra admin center and register a new application. During registration, the service lets the creator specify a redirect URI (Uniform Resource Identifier), which is the address where the Entra authentication server sends a user after successful authorisation. The criminals enter a link to their malicious site in this field. They then send out messages containing Microsoft redirect links that include the registered app’s Application ID and the chosen redirect URI. A victim who clicks lands on a site designed to steal personal data or deliver malicious software.
Kaspersky found that the attackers also use the Entra admin center to place their own content inside the service’s genuine notification emails. They probably need to buy the cheapest licence or start a trial to do so. The fraudsters type a fake message into the name field on the Overview page, then create bogus users in the Users section with invented email addresses, display names and passwords. Next, they sign in to the Microsoft My Account portal as one of these fake users and enter the victim’s real address as the backup mailbox, which is normally used for password-reset messages.
The victim then receives an unrequested verification code, with the scammers’ fraudulent text showing up in the email’s subject line and signature.
Andrey Kovtun, Email Threats Protection Group Manager at Kaspersky, said this is not the first time his team has seen scam links and messages delivered through official services rather than by impersonating a company. That, he explained, lends the messages extra credibility and makes them harder to recognise, because the usual warning signs of phishing do not apply and spotting them unaided is difficult. He urged users to install a security product with a strong anti-phishing component so they are protected automatically, even against highly sophisticated attacks.
Also read: Pakistan Presents AI Industry at AI Everything Global
For organisations, Kaspersky recommends robust email security tools, such as Kaspersky Security for Mail Server, which guards against a wide range of advanced mail-borne threats. For individuals, Kaspersky Premium includes anti-phishing features meant to help users avoid such attacks and improve their overall security.
Sohail Majeed is a Special Correspondent at The Diplomatic Insight. He has twelve plus years of experience in journalism & reporting. He covers International Affairs, Diplomacy, UN, Sports, Climate Change, Economy, Technology, and Health.






