What is the end goal of your run of the mill phishing attack?
Posted by DeifniteProfessional@reddit | sysadmin | View on Reddit | 51 comments
It's become increasingly common to see Microsoft specific attacks that are designed to get a user to log in, allowing the attacker to gain access, even with MFA enabled.
From what I've seen so far, the attacker gets in, then uses the account to bulk send the same payload to more contacts.
What's the final goal here? Is it a case of collecting as many business accounts as possible and then start manually running scams from each one after a period of time?
51 Comments
yParticle@reddit
Bartghamilton@reddit
drowningfish@reddit
Crafty_Individual_47@reddit
drowningfish@reddit
Crafty_Individual_47@reddit
drowningfish@reddit
Crafty_Individual_47@reddit
drowningfish@reddit
Crafty_Individual_47@reddit
drowningfish@reddit
rootofallworlds@reddit
Crafty_Individual_47@reddit
AmountAny8399@reddit
Crafty_Individual_47@reddit
Typical_Warning8540@reddit
DeifniteProfessional@reddit (OP)
Bartghamilton@reddit
Bartghamilton@reddit
Crafty_Individual_47@reddit
NominalDeterminate@reddit
MihaLisicek@reddit
NominalDeterminate@reddit
MihaLisicek@reddit
NominalDeterminate@reddit
EastDallasMatt@reddit
Crafty_Individual_47@reddit
bjc1960@reddit
rootofallworlds@reddit
Murky-Breadfruit-671@reddit
pdp10@reddit
patmorgan235@reddit
R8nbowhorse@reddit
Legionof1@reddit
patmorgan235@reddit
R8nbowhorse@reddit
imnotaero@reddit
imnotaero@reddit
Jeremy_Zaretski@reddit
EbbNegative1062@reddit
JustDandy07@reddit
Nick85er@reddit
LRS_David@reddit
dracotrapnet@reddit
ohyeahwell@reddit
donith913@reddit
joeyl5@reddit
donith913@reddit
Valdaraak@reddit
smnhdy@reddit
Visible_Spare2251@reddit