Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
phishing-campaign-intelligencecredential-stealer-activitysearch-ad-manipulationvoice-social-engineering

Multiple Social-Engineering Campaigns Abuse Trusted Platforms (Microsoft Teams, Vendor-Signed Email, Bing Ads/Azure)

Updated 3mo agoFirst seen Feb 11, 20264 sources

Security researchers reported several social-engineering campaigns that abuse trusted platforms to increase credibility and bypass controls. One campaign targeted wedding planners and related vendors by hijacking trust in Microsoft Teams: attackers used compromised legitimate email threads and impersonated legal professionals (e.g., czimmerman@craigzlaw[.]com) to lure victims into clicking a fake Teams meeting link that ultimately redirected to ussh[.]life/connect/teamsfinal/9/windows, a site masquerading as a Teams download page. Victims were prompted to download Windows executables consistent with information-stealer behavior (credential/browser/session-token theft and C2 exfiltration), enabling follow-on account takeover and additional phishing.

Separately, a report highlighted DKIM replay-style phishing in which criminals abuse legitimate notification/invoice workflows from PayPal, Apple, and DocuSign to generate cryptographically signed emails that pass DKIM/DMARC checks; attackers place scam content (often a fake support phone number and urgency) into user-controlled fields, send the message to themselves to obtain a “clean” vendor-signed email, then forward it to targets. Another campaign used Bing search ads to funnel users through a newly registered domain (highswit[.]space) to scam pages hosted on Microsoft Azure Blob Storage (consistent path pattern including werrx01USAHTML/index.html and a phone-number parameter), presenting fake Microsoft security warnings and directing victims to call numbers such as 1-866-520-2041 and 1-833-445-4045; Netskope observed impact across dozens of US organizations.

Share:
Multiple Social-Engineering Campaigns Abuse Trusted Platforms (Microsoft Teams, Vendor-Signed Email, Bing Ads/Azure)
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 11, 20264mo ago

Kaseya and INKY detail DKIM replay phishing via PayPal and Apple

A Kaseya report using INKY data described a phishing technique called DKIM Replay Attacks, in which criminals abuse legitimate vendor email systems such as PayPal, Apple, and DocuSign to generate cryptographically signed messages containing scam content. The report explained that attackers place malicious text such as urgent warnings and fake support numbers in user-controlled fields, then forward the unmodified signed emails to victims so they pass DKIM and DMARC checks.

Teams-themed malware campaign targets U.S. wedding vendors

Threat actors began a phishing campaign against wedding planners and related vendors in the United States, using compromised legitimate email accounts and detailed wedding-themed conversations to build trust. Victims were later sent fake Microsoft Teams meeting links that redirected to a malicious download site serving stealer malware.

Feb 10, 20264mo ago

Microsoft notified and malicious Azure containers taken down

After the Azure-hosted tech support scam was identified, Microsoft was notified about the abuse of its Blob Storage service. The malicious containers referenced in the campaign reportedly no longer served harmful content afterward.

Azure-hosted Bing ad scam impacts 48 U.S. organizations

Netskope analysts observed the Bing ad and Azure Blob Storage scam campaign affecting users across 48 organizations in the United States, including healthcare, manufacturing, and technology sectors. The campaign used standardized URL patterns and multiple Azure Blob Storage containers, indicating automated deployment and rapid scaling.

Feb 2, 20265mo ago

Bing ad scam campaign begins redirecting users to Azure-hosted fake alerts

Around 16:00 UTC on February 2, 2026, a tech support scam campaign started abusing Bing search ads to send users searching common terms to the newly registered domain highswit[.]space and then to fraudulent pages hosted on Microsoft Azure Blob Storage. The pages impersonated Microsoft security warnings and attempted to coerce victims into calling scam phone numbers for remote-access or financial fraud.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

8 LINKEDOpen in app
Affected products
1 linked
Wordpress
Organizations
7 linked
DocuSignKaseyaNetskopeApplePayPalMicrosoft CorporationINKY
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple Social-Engineering Campaigns Abuse Trusted Platforms (Microsoft Teams, Vendor-Signed Email, Bing Ads/Azure) | Mallory