Sunday, October 19, 2025
No Result
View All Result
  • Home
  • Guest Post
  • Submit Review Article
  • Contact
Somali Update
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting
No Result
View All Result
Somali Update
No Result
View All Result

Hackers Exploit Link-Wrapping Security Features to Lure Microsoft 365 Credentials

by Paul Carter
3 months ago
in News, Technology
Reading Time: 5 mins read
0
Home News
Share on FacebookShare on TwitterShare on WhatsAppShare on Telegram

Cybercriminals have found a clever way to mask phishing links using trusted security services. Their latest trick? Exploiting the very tools meant to protect users.

Trusted Services Turned Into Trojan Horses

A group of threat actors has been using legitimate link-wrapping features from major cybersecurity firms—namely Proofpoint and Intermedia—to deliver phishing emails aimed at stealing Microsoft 365 login credentials. The campaign, which ran from June through July, fooled even seasoned users by disguising malicious links as trusted, security-scanned URLs.

Link wrapping, in theory, helps protect users by scanning links and routing them through safe domains. But in this case, it became a vehicle for deception.

Instead of protecting, it redirected victims straight into the hands of attackers.

Cloudflare’s Email Security team flagged the unusual behavior after noticing email accounts protected by these services were being used to send out the wrapped phishing links. That was the first red flag: compromised accounts inside secure environments were spreading harmful payloads.

microsoft 365 phishing email screenshot 2025

Multi-Tiered Redirects Make It Harder to Catch

The attackers didn’t just rely on a single method. They layered their approach, using URL shorteners, multiple redirects, and compromised accounts. The idea was simple: if you can confuse the trail, you can increase the chance someone clicks.

First, a malicious link was shortened using a common URL shortener. Then, it was sent from a compromised account protected by either Proofpoint or Intermedia. These services automatically wrapped the link, further masking it behind their own trusted domains.

With each added layer, the real destination got fuzzier.

Cloudflare’s team noted how Proofpoint’s wrapping was particularly exploited using “multi-tiered redirect abuse.” Victims would land on a seemingly safe link, only to be funneled through redirects until they arrived at a phishing page mimicking Microsoft 365.

This wasn’t just about masking—it was a digital shell game.

Deceptive Emails Disguised as Business Tools

The phishing emails were carefully crafted to look like everyday workplace notifications. No flashy red flags. Just typical business as usual: new voicemail alerts, Microsoft Teams messages, or secure file sharing links.

A single sentence here: Nothing out of the ordinary—until you clicked.

Cloudflare’s research points to two primary types of email bait:

  • Fake Teams notifications: Clicking “Reply” sent users to a Microsoft login lookalike page.

  • Voicemail or secure document alerts: Users were lured to a page hosted on Constant Contact, posing as a Microsoft 365 login portal.

In both cases, the emails were sent from seemingly secure accounts, with URLs masked by known protection services. To the untrained eye—and even to some trained ones—these looked safe.

That’s what made them so effective.

Phishing Infrastructure Hidden in Plain Sight

The infrastructure used for these phishing pages wasn’t dark web black markets or obscure foreign hosts. It was out in the open. Constant Contact, a well-known email and digital marketing service, unknowingly hosted some of the phishing content.

In one instance, a fake Microsoft Teams message carried a link wrapped by Intermedia. That link eventually led to a Constant Contact-hosted page that mimicked Microsoft’s login interface.

This technique—using reputable services to hide malicious activity—is becoming more common. What’s new is the method of laundering phishing links through link-wrapping filters meant to stop them.

Table: Breakdown of the Campaign Mechanics

Here’s a simplified look at how this attack chain played out across services:

Step Action Service Abused
1 Link shortened via URL shortener Bitly, TinyURL, etc.
2 Sent from compromised secure account Proofpoint/Intermedia
3 Link automatically wrapped by security service Proofpoint/Intermedia
4 Redirect to phishing site hosted on legit domain Constant Contact
5 Fake login page collects Microsoft 365 creds N/A

Each step added a layer of legitimacy. By the time users reached the phishing page, many had already let their guard down.

Abusing Trust in Email Security

Security tools aren’t just technical. They’re psychological. People trust branded domains. When they see a link prefaced by Proofpoint or Intermedia, it reassures them.

That’s exactly what these attackers played on.

By compromising accounts protected by these services, the adversaries not only gained access to a platform but also to its inherent credibility. The wrapped URLs weren’t flagged by most scanners because they appeared to be already vetted.

What makes this even more concerning is that link wrapping is used across enterprise environments, not just by a few niche players. And once one compromised account starts sending these emails, the ripple effect is fast and hard to track.

An Escalation in Phishing Sophistication

Phishing tactics evolve constantly. But this campaign marks a distinct shift: attackers aren’t just fooling users—they’re fooling the systems designed to protect them.

Unlike brute-force tactics or spammy fake emails, this method was calculated and deliberate. It relied on user psychology, trusted security infrastructure, and subtlety.

  1. Cloudflare’s team says this represents a “recent development” in phishing strategy.

  2. It’s a reminder that no security measure is failproof.

  3. And when the tools meant to stop attacks are turned against us, the lines blur fast.

Paul Carter

Paul Carter

Paul Carter is a talented author and a dedicated SEO specialist. Paul's extensive knowledge of SEO techniques, including keyword research, on-page optimization, and link building strategies, allows him to develop effective strategies tailored to each client's unique needs.

Related Posts

Washington Commanders sign Treylon Burks

Commanders Turn to Treylon Burks as McLaurin Sits Out Again

2 days ago
Netflix greenlights The Granville Girls

Netflix Backs Canadian Period Romance Series The Granville Girls

2 days ago
Kim Kardashian

Kim Kardashian Opens Up on Leaving Kanye West to Protect Herself and Kids

3 days ago
top blue chip stocks

Three Blue Chip Stocks You Must Consider for Long-Term Gains

3 days ago
As the world economy enters a new phase of slower growth, traditional investment channels—from the stock market to real estate and semiconductor manufacturing—are showing signs of fatigue. With corporate profit margins falling and global liquidity tightening, one question arises: Where will the explosive wealth growth of the next decade come from? Surprisingly, it may not come from Wall Street or Silicon Valley, but from the rapidly expanding world of decentralized finance (DeFi) and digital asset infrastructure — a field currently attracting billions of dollars in institutional capital and redefining how global investors create wealth. As institutional and retail capital returns to the cryptocurrency market, Bitcoin has surged nearly 80% over the past year. Amid this accelerating momentum, BC DEFI stands out as a trusted and efficient gateway, empowering investors to seize the next wave of BTC-driven wealth growth. BC DEFI — The Secure Gateway to BTC Wealth As a top-tier provider of cloud mining and digital asset infrastructure, BC DEFI offers investors a safe, low-barrier opportunity to benefit from Bitcoin’s momentum — without any hardware or technical expertise required. Register now and receive a $20 bonus instantly, plus a fixed passive income of $0.8 per day. Seamless Access — Invest in BTC without managing mining equipment or logistics Strong Security and Compliance — Multi-layer asset protection and regulated operations Diversified Cryptocurrency Support — Beyond BTC: ETH, SOL, ADA, XRP, DOGE, LTC, and more Flexible Contracts and Transparent Returns — Daily settlements with multiple term options “Bitcoin is not just about price appreciation — it’s a pathway to wealth creation. We help investors transform market momentum into sustainable returns.” — BC DEFI Spokesperson Projected Returns (Examples) Investment Duration Daily Profit Total Return $100 2 days $5 $110 (profit $10) $500 6 days $6.5 $539 (profit $39) $6,000 7 days $93 $6,651 (profit $651) $18,000 10 days $304.2 $21,042 (profit $3,042) $2,500 16 days $35 $3,060 (profit $560) $100,000 50 days $2,300 $215,000 (profit $115,000) From small, short-term contracts to large, long-term plans, BC DEFI offers tailored and flexible opportunities for every type of investor. Register now and receive a $20 bonus instantly, plus a fixed $0.8 daily passive income. Mining the Future — Seize the Next Wave of Bitcoin Growth Bitcoin is approaching a key resistance zone, and its strong bullish momentum indicates the potential for a future breakout. For investors, maintaining BTC positions during periods of market volatility is the key to achieving higher returns. With secure and transparent operations, BC DEFI empowers users to leverage market dynamics and transform volatility into long-term wealth growth.

D’Angelo’s Death Sparks Global Outpouring from Music Icons

4 days ago
social security card

Social Security 2026 COLA Delay Frustrates Millions of Retirees

4 days ago

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

SEARCH

No Result
View All Result

TRENDING

  • Trending
  • Comments
  • Latest
Raja Rani Coupon Result

Raja Rani Result Today: Raja Rani Result 28th August Live Updates

August 28, 2024
SkymoviesHD

SkymoviesHD Proxy to Unblock Site – SkymoviesHD Movies Download

March 6, 2024
Control Bionics Secures Major US Reimbursement for NeuroNode Device

Control Bionics Secures Major US Reimbursement for NeuroNode Device

August 19, 2024
Moviesda

Moviesda Proxy to Unblock Links – Moviesda Movie Download

March 6, 2024
near lossless electrical transmission discovery by mit scientists

Near-Lossless Electrical Transmission: A Breakthrough by MIT Scientists

September 12, 2024
Bigg Boss 7 Tamil Contestants Salary

Bigg Boss 7 Tamil Contestants Salary Per Day Revealed

January 9, 2024
Vegamovies

Vegamovies Proxy to Unblock Links – Vegamovies Movies Download

March 6, 2024
iBOMMA

iBOMMA Proxy to Unblock, Movies – IBOMMA Movie Download

March 6, 2024
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

January 24, 2024
Tamilblasters

TamilBlasters Proxy – Unblock Links, Tamilblasters Movies Download

March 6, 2024

Business Ideas with Low Investment and High Profit

1
Bhutan Teer Result 2021

Bhutan Teer Result Today Live: Bhutan Teer Result 3rd January Update

1

Reasons to Join the PKT Cash Crypto Network

1
Kolkata FF Fatafat Result

Kolkata FF Fatafat Result 24th January 2024 Live Updates

1
Coinbase

Coinbase Crypto Exchange hires Jeff Horowitz as their CCO

0
Kucoin

KuCoin Scam? Office Location issue clarified

0
Nokia 5G mobile

Nokia 5G Mobile to be launched with T-Mobile soon

0
CasinoBuzz

Casino.Buzz: One of the most Informative Online Casino Review Website

0
Facebook Ban alex jones

Facebook Suspends Alex Jones for Hate Speech

0
Good Rummy Party

What Makes a Good Rummy Party?

0
Washington Commanders sign Treylon Burks

Commanders Turn to Treylon Burks as McLaurin Sits Out Again

October 17, 2025
Netflix greenlights The Granville Girls

Netflix Backs Canadian Period Romance Series The Granville Girls

October 17, 2025
Kim Kardashian

Kim Kardashian Opens Up on Leaving Kanye West to Protect Herself and Kids

October 16, 2025
top blue chip stocks

Three Blue Chip Stocks You Must Consider for Long-Term Gains

October 16, 2025
As the world economy enters a new phase of slower growth, traditional investment channels—from the stock market to real estate and semiconductor manufacturing—are showing signs of fatigue. With corporate profit margins falling and global liquidity tightening, one question arises: Where will the explosive wealth growth of the next decade come from? Surprisingly, it may not come from Wall Street or Silicon Valley, but from the rapidly expanding world of decentralized finance (DeFi) and digital asset infrastructure — a field currently attracting billions of dollars in institutional capital and redefining how global investors create wealth. As institutional and retail capital returns to the cryptocurrency market, Bitcoin has surged nearly 80% over the past year. Amid this accelerating momentum, BC DEFI stands out as a trusted and efficient gateway, empowering investors to seize the next wave of BTC-driven wealth growth. BC DEFI — The Secure Gateway to BTC Wealth As a top-tier provider of cloud mining and digital asset infrastructure, BC DEFI offers investors a safe, low-barrier opportunity to benefit from Bitcoin’s momentum — without any hardware or technical expertise required. Register now and receive a $20 bonus instantly, plus a fixed passive income of $0.8 per day. Seamless Access — Invest in BTC without managing mining equipment or logistics Strong Security and Compliance — Multi-layer asset protection and regulated operations Diversified Cryptocurrency Support — Beyond BTC: ETH, SOL, ADA, XRP, DOGE, LTC, and more Flexible Contracts and Transparent Returns — Daily settlements with multiple term options “Bitcoin is not just about price appreciation — it’s a pathway to wealth creation. We help investors transform market momentum into sustainable returns.” — BC DEFI Spokesperson Projected Returns (Examples) Investment Duration Daily Profit Total Return $100 2 days $5 $110 (profit $10) $500 6 days $6.5 $539 (profit $39) $6,000 7 days $93 $6,651 (profit $651) $18,000 10 days $304.2 $21,042 (profit $3,042) $2,500 16 days $35 $3,060 (profit $560) $100,000 50 days $2,300 $215,000 (profit $115,000) From small, short-term contracts to large, long-term plans, BC DEFI offers tailored and flexible opportunities for every type of investor. Register now and receive a $20 bonus instantly, plus a fixed $0.8 daily passive income. Mining the Future — Seize the Next Wave of Bitcoin Growth Bitcoin is approaching a key resistance zone, and its strong bullish momentum indicates the potential for a future breakout. For investors, maintaining BTC positions during periods of market volatility is the key to achieving higher returns. With secure and transparent operations, BC DEFI empowers users to leverage market dynamics and transform volatility into long-term wealth growth.

D’Angelo’s Death Sparks Global Outpouring from Music Icons

October 15, 2025
social security card

Social Security 2026 COLA Delay Frustrates Millions of Retirees

October 15, 2025
Google Meet introduces an AI-powered makeup feature

Google Meet Adds AI Makeup Tool to Help Users Look Their Best

October 14, 2025
Alec and Stephen Baldwin

Alec and Stephen Baldwin Escape Unhurt After Car Crash in the Hamptons

October 14, 2025
Explore five stocks that surged over 1,000 percent in 2025

Five Stocks That Skyrocketed Over 1,000 Percent This Year

October 13, 2025
Al Pacino and Diane Keaton

Al Pacino Regrets Never Marrying Diane Keaton After Her Death

October 13, 2025

ABOUT US

From global politics to cultural trends, we bring you comprehensive coverage and diverse perspectives. Stay connected with the international community and explore stories from around the globe. Engage with our thought-provoking articles and stay informed about the world’s most pressing issues.

Contact us at ceo.somaliupdate@gmail.com

ADVERTISE WITH US

We accept following advertisement methods in our website.

  • Guest Post
  • Sponsored Post
  • Banner Ad
  • Homepage Ad
  • Sidebar Ad
  • Niche Edit
  • Link Ad
  • Review Article

POPULAR CATEGORIES

List of Popular categories in our websites which are loved more frequently by our beloved readers.

  • AUTO
  • BUSINESS
  • CRYPTO
  • GAMBLING
  • SPORTS
  • TECH
  • HEALTH

THIS WEEK POLLS

Sorry, there are no polls available at the moment.
  • Polls Archive
  • Home
  • Guest Post
  • Submit Review Article
  • Contact

© 2023 SOMALIUPDATE - Developed by VISION

No Result
View All Result
  • Headlines
    • Politics
  • Auto
    • Bike
    • Car
  • Business
    • Finance
    • Funding
    • Internet Marketing
    • Entrepreneurship
    • Startups
    • Insurance
    • Real Estate
  • Crypto
    • Bitcoin
    • Ethereum
    • Altcoins
    • Crypto Airdrop
    • ICO News
  • Entertainment
    • Poll
    • Quiz
  • Lifestyle
    • Health
    • Fashion
    • Food
    • Romance
    • Travel
  • Sports
    • Baseball
    • Basketball
    • Cricket
    • Football
    • Hockey
    • NFL
    • Tennis
    • WWE
  • Tech
    • Gadgets
    • Hardware
    • Software
    • Android
    • iOS
    • Social Media
  • Casino
    • Betting

© 2023 SOMALIUPDATE - Developed by VISION