publishing date icon
September 1, 2023
read time icon
5 min. read

Threat feed week 35: Microsoft Planner, SharePoint, Qobuz impersonations, and fake voicemail notification

Post hero image

Table of contents

share this post

Microsoft Planner impersonation

Hox rating: ★★★★

Threat type: Advanced campaign

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 01.09.2023

This Microsoft Planner impersonation is highly customized. It includes the recipient’s name, role, and the company’s regional office address.

Microsoft Planner impersonation

The senders most likely scraped the information used from LinkedIn.

SharePoint impersonation

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 01.09.2023

This SharePoint impersonation claims that there’s a file waiting for review. It’s a classic strategy used by malicious actors in phishing emails.

SharePoint impersonation

A file awaiting review is a call to action, as the user is required to interact with the email.

Qobuz impersonation

Hox rating: ★★✩✩

Threat type: Bulk phishing

Payload: Malicious phone number

Region: Global

Analyst: Minna Herlevi

Date: 01.09.2023

This phishing email is impersonating Qobuz, a French-based music streaming service. It creates a sense of urgency by informing the user that their subscription is renewing.

Qobuz impersonation

The payload is a malicious phone number the user must call to cancel the subscription.

Fake voicemail notification

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 01.09.2023

This phishing email is pretending to be an internal voicemail notification.

Fake voicemail notification

It uses curiosity to get the recipient to click the button.

Keep up with the threat feed

Don't miss the next threat feed, and subscribe to our newsletter for the latest feed and cybersecurity content. Stay informed and stay safe!

Subscribe to Threat Feed

Subscribe to Hoxhunt's Threat Feed to get the latest phishing threats delivered to your inbox, every Friday.

Form CTA

Hoxhunt needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at anytime. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, check out our Privacy Policy.