publishing date icon
September 22, 2023
read time icon
5 min. read

Threat feed week 38: Microsoft, Federal Trade Commission, and payroll QR code impersonations

Author image
Threat Analyst Team
Post hero image

Table of contents

share this post

Microsoft impersonation

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 21.09.2023

This phishing email claims that the recipient’s access to their Microsoft email is about to expire.

Microsoft impersonation email

They're urged to click the provided link to maintain access to the account.

Microsoft Planner impersonation

Hox rating: ★★✩✩

Threat type: Advanced campaign

Payload: Malicious link

Region: Global

Analyst: Minna Herlevi

Date: 21.09.2023

This email is an advanced Microsoft Planner impersonation. The template is identical to the real notification and includes the victim’s job role and company address.

Microsoft Planner impersonation

The good visuals make it very easy to interact with the email accidentally.

Federal Trade Commission impersonation

Hox rating: ★★✩✩

Threat type: Advanced campaign

Payload: Pretext

Region: Global

Analyst: Minna Herlevi

Date: 21.09.2023

This phishing email is an advanced impersonation. It claims that the recipient's been identified as a victim of a financial scam, and must give identification to recover their stolen funds.

Federal Trade Commission impersonation

One of the links leads to the legitimate Federal Trade Commission website, which creates legitimacy.

Fake payroll summary QR code

Hox rating: ★✩✩✩

Threat type: Bulk phishing

Payload: Malicious QR code

Region: Global

Analyst: Minna Herlevi

Date: 21.09.2023

This email claims to include a link to the recipient's salary summary.

Fake payroll summary QR code

The awkward visuals make the phish easy to spot.

Keep up with the threat feed

Don't miss the next threat feed, and subscribe to our newsletter for the latest feed and cybersecurity content. Stay informed and stay safe!

Subscribe to Threat Feed

Subscribe to Hoxhunt's Threat Feed to get the latest phishing threats delivered to your inbox, every Friday.

Form CTA

Hoxhunt needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at anytime. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, check out our Privacy Policy.