Hackers Target US Business Hours in Microsoft 365 Phishing Campaign Using Direct Send
A new phishing campaign is exploiting Microsoft 365's Direct Send feature, with attackers specifically timing their attacks to coincide with US Eastern business hours.

Researchers have identified a novel phishing campaign that leverages Microsoft 365's Direct Send functionality to distribute malicious emails. This technique allows threat actors to bypass some traditional email security filters by sending emails that appear to originate from within a trusted Microsoft 365 environment.
The campaign's most notable characteristic is the timing of its attacks. Threat actors have been observed favoring US Eastern business hours, suggesting a deliberate strategy to maximize engagement and potential compromise during peak working periods. This targeted timing indicates a sophisticated understanding of user behavior and operational rhythms within organizations.
The primary objective of this campaign is to compromise Microsoft 365 accounts. By gaining access to these accounts, attackers can potentially steal sensitive information, conduct further internal phishing attacks, or disrupt business operations. The use of Direct Send makes these phishing attempts more convincing, as they may not trigger standard spam filters or be flagged as external threats.
Microsoft 365's Direct Send feature is designed for legitimate use cases, such as sending automated notifications or reports from internal applications. However, like many legitimate services, it can be abused by malicious actors if not properly secured or monitored. The attackers are exploiting this feature to make their phishing emails appear more trustworthy.
While the full scope and impact of this campaign are still under investigation, the methodology employed highlights the evolving tactics of cybercriminals targeting cloud-based productivity suites. The focus on Microsoft 365, a widely adopted platform, makes this a significant concern for businesses relying on its services.
Security professionals are advised to remain vigilant and ensure that their Microsoft 365 environments are configured securely. This includes implementing robust email filtering solutions, enabling multi-factor authentication (MFA) for all users, and conducting regular security awareness training to educate employees about the latest phishing techniques.
Further analysis of the campaign's infrastructure and specific attack vectors is ongoing. The researchers who discovered the campaign are working to provide more detailed technical indicators to help organizations defend against these threats. The exploitation of Direct Send underscores the need for continuous monitoring and adaptation of security strategies in the face of evolving cyber threats.