close
close

Microsoft Visio files used to conduct dangerous phishing attacks

Microsoft Visio files used to conduct dangerous phishing attacks


  • Scammers integrate malicious links into Microsoft Visio files
  • The files are distributed via compromised email accounts
  • The goal of the campaign is to steal Microsoft 365 credentials

Security researchers at Perception Point have discovered a new two-step phishing campaign aimed at stealing people’s data Microsoft 365 login details. It includes compromised email accountscompromised SharePoint accounts and some convincing (but fake) purchase orders.

The attack starts with a compromised Microsoft SharePoint account, where the criminals upload a file using Microsoft Visio – the company’s tool for creating professional charts and diagrams, creating files with the .VSDX extension.