Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (2024)

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (2)

Have you heard of Microsoft Sway? If you haven’t, there’s a good chance your users don’t know about it either.

That’s why this content creation service is used in phishing attacks. Attackers can turn Microsoft Sway into most any site they like, causing both Outlook and even the most savvy recipients to trust sway.com links.

Why are hackers using Microsoft Sway?

Sway is a web app for creating PowerPoint-like presentations and newsletters. It also serves as an easy point-and-click way to create a landing page that might fool your users.

For these reasons, Microsoft Sway has become a popular place for hackers to host phishing sites to run scams like the one below.

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (3)

You’ll notice that:

  1. Microsoft Sway pages are hosted on office.com. With that stamp of legitimacy, Sway pages bypass URL filters and any investigation that your users are capable of.
  2. If your users are logged into an Office account, Sway pages appear wrapped in Office 365 styling with accompanying menus to be even more convincing.
  3. The Sway page will include trusted brand names. (Most commonly, the spoofed brands are Microsoft-affiliated, just like the SharePoint logo shown in the example above.)
  4. Hackers intend for victims to click the hyperlinked URL “FAX MESSAGE” at the bottom. These links download a malicious file or lead to spoofed login page.

Why are Microsoft Sway attacks so effective?

To convince potential victims to land on the Sway phishing page, hackers send emails with notifications for voicemails or faxes.

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (4)

In the email above, the same tricks that fool your users also fool Microsoft security:

  1. The email was sent from an onmicrosoft.com email address, so Microsoft trusts the domain, enabling it to pass most of the basic spoof filters.
  2. Consistent branding helps convince potential victims that the email contains a fax. (This is why image analysis is vital in phish detection.)
  3. The recent date next to “Fax Received at:” suggests this attack is more sophisticated, using dynamically generated text rather than cut-and-pasted text.
  4. The preview image of the fax looks too important to ignore.
  5. The two important links in the email to the fax and the faxing service both point to sway.office.com. Even if users are unfamiliar with Sway, they have been taught to trust office.com. Microsoft trusts Sway and its other productivity services implicitly, so this URL will bypass even the strictest SafeLinks settings.
  6. The other links in the email body point to another trusted site: LinkedIn. Similar attacks use real URLs from trusted sites that lead to the page they promise.

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (5)

Indicators of Compromise

Avanan clients targeted in the Microsoft Sway attack received the same message from multiple low-traffic, low-reputation senders. Because the hackers are using multiple senders and domains in this attack, Block Listing them won’t work.

Instead, we’ve seen many clients Block List sway.office.com in their web filters. Unless your organization actively uses Microsoft Sway, you should consider blocking Sway links.

Using Microsoft Services to Phish Microsoft

Instead of sending potential victims to a compromised website that might be blocked by browsers and Block Lists, the URL in this attack goes to sway.office.com. Because the phishing page is hosted on Microsoft, it will always be considered 100% safe.

Microsoft, your users, your desktop antivirus, your browsers, and your DNS filters can’t stop this attack. Avanan identified the Sway attack using link analysis and sender reputation checks. Because Avanan deploys within Office 365, our algorithm catches attacks that Microsoft misses, like this one, before they hit the inbox.

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (6)

Microsoft Sway Scams Used By Cybercriminals to Phish Office 365 (2024)
Top Articles
Summary of Changes
Cost of Living in Kuwait City, Kuwait. Sep 2024 prices in Kuwait City.
Jordanbush Only Fans
Hotels Near 625 Smith Avenue Nashville Tn 37203
Avonlea Havanese
Fat Hog Prices Today
Culver's Flavor Of The Day Wilson Nc
Nikki Catsouras Head Cut In Half
CSC error CS0006: Metadata file 'SonarAnalyzer.dll' could not be found
Does Publix Have Sephora Gift Cards
Anki Fsrs
Florida (FL) Powerball - Winning Numbers & Results
Which Is A Popular Southern Hemisphere Destination Microsoft Rewards
REVIEW - Empire of Sin
Things To Do In Atlanta Tomorrow Night
Raleigh Craigs List
978-0137606801
2021 Lexus IS for sale - Richardson, TX - craigslist
Morgan And Nay Funeral Home Obituaries
Viprow Golf
10-Day Weather Forecast for Florence, AL - The Weather Channel | weather.com
Po Box 35691 Canton Oh
Dumb Money, la recensione: Paul Dano e quel film biografico sul caso GameStop
Mccain Agportal
*Price Lowered! This weekend ONLY* 2006 VTX1300R, windshield & hard bags, low mi - motorcycles/scooters - by owner -...
Cvs El Salido
Graphic Look Inside Jeffrey Dahmer
Homeaccess.stopandshop
Wics News Springfield Il
Cars & Trucks - By Owner near Kissimmee, FL - craigslist
What Is a Yurt Tent?
Tinyzonehd
Encore Atlanta Cheer Competition
Downloahub
Hannah Jewell
Club Keno Drawings
123Moviestvme
Makemkv Key April 2023
Devotion Showtimes Near Mjr Universal Grand Cinema 16
Ippa 番号
Merge Dragons Totem Grid
Restored Republic December 9 2022
Jetblue 1919
Nina Flowers
30 Years Of Adonis Eng Sub
Online-Reservierungen - Booqable Vermietungssoftware
Ssc South Carolina
Tacos Diego Hugoton Ks
Anonib New
Deshuesadero El Pulpo
Roller Znen ZN50QT-E
Mazda 3 Depreciation
Latest Posts
Article information

Author: Otha Schamberger

Last Updated:

Views: 6028

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Otha Schamberger

Birthday: 1999-08-15

Address: Suite 490 606 Hammes Ferry, Carterhaven, IL 62290

Phone: +8557035444877

Job: Forward IT Agent

Hobby: Fishing, Flying, Jewelry making, Digital arts, Sand art, Parkour, tabletop games

Introduction: My name is Otha Schamberger, I am a vast, good, healthy, cheerful, energetic, gorgeous, magnificent person who loves writing and wants to share my knowledge and understanding with you.