Cyberattack News

Hackers Leveraging Microsoft Visio Files & SharePoint For Two-Step Phishing Attack

A new sophisticated phishing technique utilizes Microsoft Visio files and SharePoint in a two-step phishing attack.

This two-step attack method represents a significant evolution in phishing tactics. It exploits users’ trust in familiar Microsoft tools to bypass security measures and steal credentials.

The attack begins with compromised email accounts sending legitimate messages, often containing business proposals or purchase orders.

Attend a Free Webinar on How to Maximize Cybersecurity Program ROI

These emails include links to SharePoint-hosted Microsoft Visio (.vsdx) files, a format commonly used for creating flowcharts and diagrams in professional settings.

Once a victim clicks on the link, they are directed to a SharePoint page containing the malicious Visio file. The file typically includes a “View Document” button, which users are instructed to click while holding down the Ctrl key.

This seemingly innocuous action is designed to evade automated security scans, as it requires human interaction that bots cannot replicate.

Clicking the button redirects the user to a fake Microsoft 365 login page, where their credentials are captured if entered.

Two-step phishing attack

The use of compromised email accounts and legitimate Microsoft services like SharePoint adds multiple layers of perceived authenticity to the attack, making it particularly deceptive.

Perception Point researchers have observed a significant increase in these Visio-based phishing attempts, targeting hundreds of organizations worldwide.

The tactic takes advantage of the fact that Visio files are rarely flagged as threats by traditional security systems, unlike more common file types such as PDFs or Word documents.

Microsoft has acknowledged the growing misuse of its services in phishing campaigns, highlighting the need for increased vigilance.

To protect against such threats, experts recommend verifying sender identities, enabling multi-factor authentication, and implementing advanced email security solutions that can detect unusual file types and behaviors.

As cybercriminals continue to refine their methods, this new attack vector serves as a reminder of the importance of ongoing user education and the need for robust, multi-layered security approaches in today’s rapidly evolving threat landscape.

Free Email Phishing Playbook (PDF) for Handling Attacks Efficiently -> Download Now

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

2 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

3 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

5 hours ago