yazamtech.com ↗

Security Intelligence Report
Phishing Attack Exploiting Microsoft Services

A new and sophisticated wave of attacks targets organizations by leveraging legitimate Microsoft services. The attacker executes no suspicious files and relies on no classic phishing sites. Instead, it exploits the trust that users and security systems place in Microsoft Power BI, Authentication Broker, and the OAuth Device Code Flow protocol, getting the victim to authorize full access to their corporate account without the attacker ever knowing their password.

Microsoft Power BI

Landing Page: The Entry Point

A Business Intelligence platform for data analysis. In this attack scenario, the attacker leverages a legitimate page at app.powerbi.com to redirect the victim and lead them through the process, without any security system raising an alert.

OAuth 2.0 Device Code Flow

Core of the Attack:
Credential Theft

An authentication protocol designed for browserless devices. The attacker exploits it to generate an access code the victim willingly enters, thereby approving a connection request initiated by the attacker, without realizing it.

Microsoft Authentication Broker

The Breach Point: Token Transfer

The authentication service that mediates between applications and the user's account. Once the victim enters the code, Microsoft issues an Access Token directly to the attacker's server, no password required.

The attack unfolds across five consecutive stages, with the victim seeing only familiar, legitimate services at every step.

1

Malicious Email Distribution from a Compromised Account

The attacker breaches a corporate email account and sends an email to the victim's contact list, with a "View Completed Document" button. The email arrives from a known sender, so suspicion levels remain low.

מייל תקיפה לדוגמא מצונזר
Real attack email sent from a breached corporate account
2

Landing Page on Microsoft Power BI

Clicking the link leads to a legitimate page at app.powerbi.com, not a suspicious site. Security systems do not flag the domain, and the user sees a familiar Microsoft service.

דף Power BI
Official Microsoft Power BI landing page
3

Generating an Access Code from Microsoft

The victim is required to pass through a Cloudflare Verification screen, a barrier that prevents automated analysis of the page. They are then shown a page impersonating the DocuSign interface, displaying an access code generated by the attacker's application on Microsoft. Clicking the Open button takes the victim directly to Microsoft's official website to complete the authentication process.

Cloudflare Verification screen blocks automated security tools
Access code displayed to the victim on a page impersonating DocuSign
4

Victim Authentication on Microsoft's Official Website

The victim is redirected to the official login.microsoftonline.com and enters the code. From here, two paths exist: if the victim is already signed into Microsoft 365, authentication completes automatically with no password entry required. If not, they are prompted for their username and password. In both cases, everything takes place within an authentic Microsoft interface with an HTTPS padlock, no suspicious signs whatsoever.

Enter access code screen, official Microsoft address
Sign in screen, official Microsoft address
Password entry screen, Microsoft's official website
5

Corporate Account Takeover

Microsoft issues an Access Token and Refresh Token directly to the attacker's server, without needing the user's password.
For a regular user, the attacker gains access to their corporate emails and files.
For an Admin user, the impact can extend to account and permission management across the organization.

Every Component Appears Legitimate

Microsoft Power BI, Microsoft Authentication Broker, Cloudflare, DocuSign, and OAuth are entirely legitimate tools. The problem arises from their combination. Many security systems fail to recognize the chain of actions as a threat, since each component on its own is familiar and safe. Because the emails originate from genuine corporate accounts, a single compromised account is enough to turn a trusted vendor into a distributor of the attack to all of their contacts.

Even Experienced Users Are Affected

There is no visual suspicious sign anywhere in the process. The user sees Microsoft, the browser shows a padlock, and the authentication flow looks real. Yet behind the scenes, the authorization request was created by the attacker and the tokens are sent to them. Recent attacks are most commonly identified when arriving via email, but they can also arrive through browser downloads, chat platforms, and interorganizational file transfer systems.

The attack is designed to bypass each defensive layer individually. The table below shows how each common security system fails against this attack chain, and why a multilayered approach is required.

Security System Why It Fails Against This Attack
Firewalls Traffic passes through legitimate Microsoft and Cloudflare domains. There is no suspicious IP to block.
Antivirus & Antimalware No malicious file exists in the attack chain. Any system based on file analysis, Antivirus, Antimalware, and attachment scanners, is unable to detect the threat. Everything relies on links, codes, and a legitimate OAuth protocol.
Secure Email Gateways / Mail Relays The email is sent from a legitimate account of a breached organization. The embedded link points to app.powerbi.com, a trusted domain.
Web Proxies & Secure Browsers All domains in the chain (powerbi.com, cloudflare.com, microsoftonline.com) appear on allowlists. URLbased blocking is ineffective.
EDR / XDR The authentication process looks completely normal from an endpoint perspective. No malicious code is executed, only regular user browser activity.
WAF Requests pass through standard Microsoft APIs. No unusual payload, injection, or recognized attack pattern exists to filter.
Sandboxes The Cloudflare Verification screen blocks automated scanners. There is no file to analyze, only an authentication flow that appears legitimate.
Every security system sees only its own segment of the chain, and that segment appears normal. Only analysis of the full action chain can expose the attack.
Effective defense requires simultaneous coverage of all entry channels: email, browsers, chat, and file transfer systems.

Defense Must Be MultiLayered

Since the attack can originate through multiple channels, defense must cover all relevant entry points: email, browser, chat, and file transfer systems. YazamTech offers full coverage of all major channels.

Email Channel

Yazam Email ↗

Protection for emails and files received via electronic mail, as part of a multilayered response to attack scenarios that begin in the email channel.

Browser Channel

Yazam Processes ↗

protection for files downloaded through browsers, actively disarming embedded threats before they reach the endpoint.

Chat Channel

Yazam Processes ↗

Detection of suspicious files and links arriving via Teams, WhatsApp, Telegram, and additional communication platforms.

File Transfer

Yazam MFT ↗

Scanning and filtering of files transferred between organizations via MFT systems, covering an entry point that is often overlooked.