Microsoft has been converting Office to a subscription system for many years. The features of cloud collaboration and seamless synchronization make work smoother and attract many users to join. Now comes the risk that Microsoft 365 users may face. Microsoft has issued a warning to Office 365 users, asking everyone to be careful about potential malicious software that is invading users’ privacy by sending phishing emails. You must be on guard!

Microsoft warns: Phishing emails infiltrate Office 365 users
Microsoft has issued a warning to Office 365 users and pointed out on its official Twitter that a potentially malicious application is sending phishing emails to Office 365 users. The email will ask the user to obtain OAuth permissions to create inbox rules, compose and read email content, and add projects to the calendar. In addition, it will also ask the user for permission to access contacts.
Microsoft is tracking a recent consent phishing campaign, reported by @ffforward, that abuses OAuth request links to trick users into granting consent to an app named ‘Upgrade’. The app governance feature in Microsoft Defender for Cloud Apps flagged the app’s unusual behavior. pic.twitter.com/YMUHvEMYYD
— Microsoft Security Intelligence (@MsftSecIntel) January 21, 2022
The reason why we are so wary of phishing emails is that unscrupulous people have used the OAuth service to access user accounts in the past. Since this phishing email will mislead users, Microsoft is worried that if users fail to grant permissions for a while, malicious activities will occur in the account.从本质上来说,网路钓鱼是指攻击者利用授权请求让用户向其帐号授予通行证,使攻击者能够连接进入访问你的个人邮件资讯,即使它没有马上发出攻击,也能让入侵者有机会在你的收件匣中建立转寄规则,从而允许未来继续攻击其他网站。

After Twitter user @fffforward discovered the malicious app, Microsoft has disabled the app and alerted affected users. If you’re using Microsoft Office 365, be wary of any authorization request emails you receive.
How to avoid authorization phishing scams?
Authorization fraud methods are ubiquitous. If you want to avoid falling into such a trap, be sure to pay attention to the source of the authorization request. In addition, you must also review and judge the authorization requirements for third-party application access accounts.

Granting access to your email to any third-party app (especially one that uses Microsoft’s name to spoof certain permissions) could make it easy for an attacker to break into your other accounts by forwarding emails for password resets and other important security notifications. You can also keep an eye on the email addresses that send these authorization requests to verify that they are officially owned.
Source: KOCPC Chinese