Observable: Multiple, see Details Observable Type: Domains, Email Subjects
Details:
We have identified a new phishing/reverse phishing campaign that uses Microsoft Entra tenant invitations to trick recipients into calling a telephone number, referencing a fictitious bill. From the phone number, normal TOAD TTPs are in play (install remote access tools, etc.). The use of Entra Guest user invitations seems solely to take advantage of the Message field in the Guest User invitation.
Now I see the same thing, but then again our DMARC checks always fail on the last hop because our internal gateway is not an authorized sender for Microsoft. If you look one hop above, it should pass. We see passes for ours.
Dumb question: I don’t work directly in Entra much. Is there a way to query what tenants a user account is a part of? I found some posts that say not due to the required read access to the other potential tenants, but it seems like an admin should be able to see all tenants that their users have joined.