CRN
  • Home
  • News
  • Security

Scammers exploit Azure blob stores, Optus accounts

By Nico Arboleda on Feb 15, 2019 9:45AM
Scammers exploit Azure blob stores, Optus accounts

In The Spotlight

Partners join Ingram Micro, Vertiv for cooking lessons

Meet the Customer Experience finalists in the 2022 CRN Impact Awards

Meet the Business Transformation finalists in the 2022 CRN Impact Awards

Meet the Workforce Empowerment finalists in the 2022 CRN Impact Awards

Scammers are using compromised Optus accounts and Microsoft Azure blob storage to dupe unsuspecting users into clicking malicious links.

Advisories from email and web filtering software vendor Mailguard this week highlighted two scams being conducted under the name of the telco and software giant, respectively. 

One scam, reported yesterday, has been impersonating Microsoft and OneDrive and one drive to convince recipients to click a link in order to access a remittance advice file that had supposedly been shared with them.

The link in the email leads them to a fake website, some of which are hosted on Microsoft's Azure blob store in order to fool a user with a real "windows.net" URL. The full email would look like:

“https://proofpoint XX.blob.core.windows.net/advice/view.html”

The fake website pretends to be a portal for Microsoft Office 365, complete with a pop-up prompting users to enter their login details.

"[The scam] is a good reminder of how innocent-looking, plain emails can, in fact, be malicious, despite where they purport to be from," Mailguard said.

"As simple as they may seem, these attacks are happening all too regularly, and with devastating effect."

In a separate case reported yesterday, a set of emails, arriving in multiple variations from remittance advice to car insurance document scams, claimed to originate from Optus. The emails were all the more compelling because they were coming from the "optusnet.com.au" domain.

"MailGuard understands they originate from a large number of compromised email addresses using the same domain," the scam advisory read.

"The format of these emails is similar, with most appearing in plain-text form," the Mailguard advisory read. "They advise the recipient of a document that is available for them, with a link to access the said document. In most cases, the links lead unsuspecting recipients to a malicious file download."

The email doesn't include an attachment but has a link to a Google Docs hosted Word document containing macros.

The scam report came in a week where a number of Optus customers had taken to social media to report issues with their Optus accounts, wherein they would log into their Optus accounts to be greeted by another name, suggesting account tampering.

Yo someone tell @optus some shit is going down with My Account. Page refreshes every 2 seconds and when I managed to click into my account (chrome auto fills my deets) I was Vladimir? Yea i ain’t Vladimir pic.twitter.com/m1h2OMNLdY

— �� Tommy �� (@ShiftyChips) February 14, 2019

 

@Optus was live chatting earlier but it dropped out, I’m getting this when trying to login to My Account at https://t.co/pekhxR8fwJ i then can’t access anything pic.twitter.com/HTtqoPBXPX

— Dave 'Cruedevil' (@Cruedevil) February 14, 2019

 

@Optus i think there is something wrong with the my account page on your website. It logged me in as someone else.

— Alex Watts (@alexjwatts83) February 14, 2019
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © CRN Australia. All rights reserved.
Tags:
azure microsoft optus security

Partner Content

Microsoft, Yealink and Alloy’s roadshows fire up the Australian channel
Promoted Content
Microsoft, Yealink and Alloy’s roadshows fire up the Australian channel
Ransomware protection has become a critical channel upsell
Promoted Content
Ransomware protection has become a critical channel upsell
Is business nbn Enterprise Ethernet the future of business connectivity for MSPs?
Promoted Content
Is business nbn Enterprise Ethernet the future of business connectivity for MSPs?
How Yealink powers the Future Workplace with Microsoft Teams collaboration devices
Promoted Content
How Yealink powers the Future Workplace with Microsoft Teams collaboration devices
Tradewinds has turned unified communications into an easier upsell
Promoted Content
Tradewinds has turned unified communications into an easier upsell

Sponsored Whitepapers

How vulnerability scans identify & protect against cyberthreats before criminals locate them
How vulnerability scans identify & protect against cyberthreats before criminals locate them
Monitoring & automation: A primer for MSPs
Monitoring & automation: A primer for MSPs
Endpoint Detection and Response
Endpoint Detection and Response
How to put your infrastructure into overdrive
How to put your infrastructure into overdrive
MSPs: Stack your solutions
MSPs: Stack your solutions
By Nico Arboleda
Feb 15 2019
9:45AM
0 Comments

Related Articles

  • Canberra security ISV ArchTIS gets NC Protect platform on Microsoft Azure Marketplace
  • Microsoft Azure DevOps targeted by hackers
  • Microsoft specialist Arinco dips its toes into cyber due to customer demand
  • Four new Microsoft Azure vulnerabilities reported
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Bidding war for MOQ Limited heats up

Bidding war for MOQ Limited heats up

Servers Australia discloses "malicious activity" impacting some Sydney services

Servers Australia discloses "malicious activity" impacting some Sydney services

Global SIs top Gartner's cloud IT transformation providers report

Global SIs top Gartner's cloud IT transformation providers report

Reserve Bank of Australia launches digital currency project

Reserve Bank of Australia launches digital currency project

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.