Back to All Attacks
Attack Details
Attack Date:
May 10, 2022

SharePoint Fake Document Credential Phishing Attack

Initial Email Content

Subject
New Project 10-05-2022
Body

Hi,

A new online SharePoint proposal document has been sent to your desk, kindly see pdf using the secured URL below.

VIEW DOCUMENT.PDF

This is a sensitive and secured file. Please use your sign in details to access document

If you have any question, please don’t hesitate to email me.

Thanks for understanding,


[Recipient Signature]

Attack Screenshots

No items found.

Malicious Artifacts

Additional Indicators of Compromise

Type

Description

No items found.

Attack Description

This link-based attack impersonates SharePoint using a self-addressed spoofed email address and a fake document theme to steal credentials.

Analysis Overview

Tactic
Self-Addressed Spoofed Email
Goal
Credential Theft
Impersonated Party
Vector
Link-based
Theme
Fake Document
Language