OneDrive Phishing Alert: Cyber Sleuths Expose Crafty Pastejacking Campaign

Cybersecurity researchers have identified a sneaky phishing campaign called OneDrive Pastejacking, which tricks Microsoft OneDrive users into running a malicious PowerShell script. The scam uses convincing fake error messages to guide victims into compromising their own systems, showing that even your cloud storage can have…

Hot Take:

Ah, phishing – the spam email of the cybersecurity world. What’s next? “Your computer is infected! Click here to win a free iPhone!” These guys are just one Nigerian prince away from a full bingo card. It’s 2023, people! If we’re still falling for “Click here to fix your OneDrive,” we might as well start replying to those “You’ve won a lottery” emails. Kudos to the bad guys for creativity, though.

Key Points:

  • New phishing campaign targets Microsoft OneDrive users using social engineering tactics.
  • Uses an HTML file in email to simulate a OneDrive page and prompt users to execute a malicious PowerShell script.
  • Campaign named OneDrive Pastejacking, observed in multiple countries including the U.S., South Korea, and Germany.
  • Phishing techniques increasingly sophisticated, leveraging trusted platforms such as Microsoft Office Forms and Cloudflare R2.
  • SEG scanning methods exploited to deliver malware like Formbook disguised as MPEG files in ZIP archives.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here