---
title: "Two New Phishing Exploits Threaten Microsoft Users | DuoCircle"
description: "Microsoft is a big target for hackers, and it seems that they have recently come up with two new and novel phishing attack methods to go after the company’s."
image: "https://www.duocircle.com/images/og-default.png"
canonical: "https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/"
---

Quick Answer

Two phishing techniques targeting Microsoft customers bypass traditional defenses. The first delivers an HTML attachment that, when opened, renders a fake Microsoft login page as a popup directly inside the email client. Because the credential-harvesting form is embedded in the attachment rather than hosted on a remote server, URL-based filters and reputation lookups never trigger. The second uses a malicious Office 365 add-in. The lure impersonates a SharePoint or OneDrive file share; clicking the link prompts the user to install an add-in that grants the attacker full OAuth access to the victim's mailbox, contacts, and OneDrive files, no password required. Microsoft allows side-loaded add-ins to bypass the Office Store review, so defenders need to restrict add-in installation by policy and monitor consented OAuth grants.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Two%20New%20Phishing%20Exploits%20Threaten%20Microsoft%20Users&url=undefined%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F&title=Two%20New%20Phishing%20Exploits%20Threaten%20Microsoft%20Users "Share on Reddit") [ ](mailto:?subject=Two%20New%20Phishing%20Exploits%20Threaten%20Microsoft%20Users&body=Check out this article: undefined%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F "Share via Email") 

![phishing](https://media.mailhop.org/duocircle/images/2019/12/spf-record-check-6678.jpg) 

_Microsoft is a big target for hackers, and it seems that they have recently come up with two new and novel phishing attack methods_ to go after the company’s customers. And the thing that makes these **phishing tactics** so scary, is that they bypass traditional security measures.

The first of these phishing attacks, reported by [Latest Hacking News](https://latesthackingnews.com/2019/12/09/microsoft-phishing-attack-bypasses-security-by-creating-local-login-form/), _uses a local login form to bypass security_. The attack starts with “an email notifying users about a ‘copy of payment notification’.” The email doesn’t say much, but does contain an HTML attachment.

_The HTML attachment is what makes this phishing attack unique_. “Unlike most HTML code in phishing attacks that redirect users to **phishing websites**, the one in this attack behaved differently. Opening the attachment displayed a login page as a pop-up.”

The login page looks like a Microsoft page, but of course it’s not. _It’s a phishing page designed to steal credentials_. And what make is so hard to detect is the page is actually **embedded right in the email** and not on some malicious server somewhere. _This is a really clever phishing exploit and one that is hard to detect_.

The other phishing attack, reported by [PhishLabs](https://info.phishlabs.com/blog/office-365-phishing-uses-malicious-app-persist-password-reset), “_uses a malicious Microsoft Office 365 App to gain access to a victim’s account without requiring them to give up their credentials to the attackers_.” Talk about hard to detect.

As detailed by PhishLabs, “In this technique, the attacker sends a traditional phishing message impersonating an internal SharePoint and OneDrive file-share that uses **social engineering** to coerce the victim into clicking an embedded link. The lure itself is nothing special. _The threat actor uses the credibility of a commonly seen business process, which disarms the victim_.”

So, what’s so clever about this exploit? It takes advantage of the fact that Office 365 allows add-ins and apps to be installed to ostensibly increase the utility of the various Office 365 applications. _This particular exploit is nothing more than presenting the user with an opportunity to install an Office 365 add-in_. An add-in that “grants full control of your Office 365 account to the attacker. This is everything from granting access to your inbox, your contacts, and any files you have access to on OneDrive.”

What makes it even worse is that “Microsoft allows Office 365 Add-Ins and Apps to be installed via **side loading** without going through the Office Store, and thereby avoiding any review process. _This means that a threat actor can deliver a malicious app from the infrastructure that they control to any user that clicks a URL and approves the requested permissions_. In this case, the result is complete control over your Office 365 Account.”

If you use Office 365, like many people do, whether you know it or not, _you are under constant attack from very clever hackers exploiting all the weaknesses in the Microsoft ecosystem_. You simply cannot protect yourself from every possible **Microsoft exploit**. You’re going to need some help.

## Meet some help

[Phishing Protection](/email/phishing-protection) from DuoCircle.com. It protects you from all the advanced phishing attacks on Office 365, including the two newest ones covered here, by using **real-time link click protection**. With real-time link click protection, every time you click on an embedded link or open an attachment, before the action can be completed, Phishing Protection makes sure it’s legitimate. And if it isn’t, it blocks it and keeps you safe.

_Cloud-based Phishing Protection doesn’t require any hardware, software or maintenance. It sets up in 10 minutes, comes with 24/7 live tech support and only costs pennies per user per month_. The Office 365 attacks are not going to stop. Only you can protect yourself. Protect yourself with **Phishing Protection** from [DuoCircle](/).

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

Brad Slavin 

General Manager

General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.

## Secure your email infrastructure

Protect, authenticate, and deliver. Contact our team to find the right solution.

[Contact Sales](/contact/) [Explore Products](/products/) 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F) [ ](https://twitter.com/intent/tweet?text=Two%20New%20Phishing%20Exploits%20Threaten%20Microsoft%20Users&url=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.duocircle.com%2Fblog%2Fphishing-protection%2Ftwo-new-phishing-exploits-threaten-microsoft-users%2F) Copy 

Related Articles

- [ ![AI-Generated Phishing](https://media.mailhop.org/duocircle/images/2026/04/spf-record-4522.jpg)  AI-Generated Phishing Has Eliminated the Typo: Why Traditional Email Filters Are No Longer Enough Phishing ](/blog/ai-generated-phishing-eliminates-typos-making-traditional-email-filters-ineffective/)
- [ ![spf-permerror-4555](https://media.mailhop.org/duocircle/images/2023/05/spf-permerror-4555.jpg)  10 Applications of ChatGPT that Hackers Are Already Exploiting Phishing ](/blog/phishing-protection/10-applications-of-chatgpt-that-hackers-are-already-exploiting/)
- [ ![Email-Based Cyber-Attacks](https://media.mailhop.org/duocircle/images/2016/03/spf-record-tester-4455.jpg)  65% of Global Businesses Ill-Equipped to Defend Against Email-Based Cyber-Attacks Phishing ](/blog/phishing-protection/65-global-businesses-ill-equipped-defend-email-based-cyber-attacks/)
- [ ![Email-based Ransomware Attacks](https://media.mailhop.org/duocircle/images/2018/02/email-smtp-service-7834.jpg)  7 Ways to Protect Your Organization from Email-based Ransomware Attacks Phishing ](/blog/phishing-protection/7-ways-protect-organization-email-based-ransomware-attacks/)

## Related Articles

[  Phishing 11m  AI-Generated Phishing Has Eliminated the Typo: Why Traditional Email Filters Are No Longer Enough  Apr 28, 2026 ](/blog/ai-generated-phishing-eliminates-typos-making-traditional-email-filters-ineffective/)[  Phishing 5m  10 Applications of ChatGPT that Hackers Are Already Exploiting  May 3, 2023 ](/blog/phishing-protection/10-applications-of-chatgpt-that-hackers-are-already-exploiting/)[  Phishing 4m  65% of Global Businesses Ill-Equipped to Defend Against Email-Based Cyber-Attacks  Mar 29, 2016 ](/blog/phishing-protection/65-global-businesses-ill-equipped-defend-email-based-cyber-attacks/)[  Phishing 9m  7 Ways to Protect Your Organization from Email-based Ransomware Attacks  Feb 11, 2018 ](/blog/phishing-protection/7-ways-protect-organization-email-based-ransomware-attacks/)

```json
{"@context":"https://schema.org","@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}],"sameAs":["https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.facebook.com/duocirclellc","https://www.g2.com/products/phish-protection-by-duocircle/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://support.duocircle.com"},"knowsAbout":["Email Security","Email Authentication","SPF","DKIM","DMARC","Phishing Protection","Spam Filtering","SMTP Relay","Email Deliverability","Email Forwarding"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DuoCircle LLC","url":"https://www.duocircle.com","description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Two New Phishing Exploits Threaten Microsoft Users","description":"Microsoft is a big target for hackers, and it seems that they have recently come up with two new and novel phishing attack methods to go after the company’s.","url":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/","datePublished":"2019-12-18T16:44:24.000Z","dateModified":"2025-05-23T17:42:06.000Z","dateCreated":"2019-12-18T16:44:24.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/"},"articleSection":"phishing-protection","keywords":"","wordCount":616,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/12/spf-record-check-6678.jpg","caption":"phishing","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}},{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":2,"name":"Phishing"},{"@type":"ListItem","position":3,"name":"Two New Phishing Exploits Threaten Microsoft Users","item":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/"}]}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://www.duocircle.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://www.duocircle.com/blog/"},{"@type":"ListItem","position":3,"name":"Phishing","item":"https://www.duocircle.comundefined"},{"@type":"ListItem","position":4,"name":"Two New Phishing Exploits Threaten Microsoft Users","item":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/"}]}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Two New Phishing Exploits Threaten Microsoft Users","description":"Microsoft is a big target for hackers, and it seems that they have recently come up with two new and novel phishing attack methods to go after the company’s.","url":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/","datePublished":"2019-12-18T16:44:24.000Z","dateModified":"2025-05-23T17:42:06.000Z","dateCreated":"2019-12-18T16:44:24.000Z","author":{"@type":"Person","@id":"https://www.duocircle.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://www.duocircle.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin runs DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. His focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","name":"DuoCircle LLC","url":"https://www.duocircle.com","logo":{"@type":"ImageObject","url":"https://www.duocircle.com/images/duocircle-logo.png"},"description":"DuoCircle is a portfolio of specialized email products covering protection, authentication, delivery, and routing. We deliver about 90% of category-leader capability at roughly half the price, backed by experts who own the outcome. Trusted by 50,000+ organizations since 2014.","subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://www.duocircle.com/blog/phishing-protection/two-new-phishing-exploits-threaten-microsoft-users/"},"articleSection":"phishing-protection","keywords":"","wordCount":616,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/duocircle/images/2019/12/spf-record-check-6678.jpg","caption":"phishing","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```
