Phishing/TOAD Campaign via Entra Invites

Observable: Multiple, see Details
Observable Type: Domains, Email Subjects

Details:

We have identified a new phishing/reverse phishing campaign that uses Microsoft Entra tenant invitations to trick recipients into calling a telephone number, referencing a fictitious bill. From the phone number, normal TOAD TTPs are in play (install remote access tools, etc.). The use of Entra Guest user invitations seems solely to take advantage of the Message field in the Guest User invitation.

This field can be arbitrarily long, and is used to create a phishing lure

IoCs

Indicator Type Description
invites@microsoft[.]com Email Sender address for Entra invites
invited you to access applications within their organization String Email Subject substring to search for Guest User invitations
CloudSync String Attacker Tenant Name
Advanced Suite Services String Attacker Tenant Name
TenantHub String Attacker Tenant Name
Unified Workspace Team String Attacker Tenant Name
Advanced Suite Services String Attacker Tenant Name
x44xfqf.onmicrosoft[.]com Domain Attacker Tenant Domain
woodedlif.onmicrosoft[.]com Domain Attacker Tenant Domain
xeyi1ba.onmicrosoft[.]com Domain Attacker Tenant Domain
x44xfgf.onmicrosoft[.]com Domain Attacker Tenant Domain
18052948531 Telephone Number Number observed in phishing messages
1 Like

Add me to the list of targeted orgs. :smiling_face_with_tear:

1 Like

Any differences in Tenant Names or additional domains?

Not yet. I’m walking someone through hunting it right now.

SPF, DMARC, and DKIM fail but allowed through because MS allows MS. :upside_down_face:

1 Like

Now I see the same thing, but then again our DMARC checks always fail on the last hop because our internal gateway is not an authorized sender for Microsoft. If you look one hop above, it should pass. We see passes for ours.

1 Like

Public report is live: TOAD Attacks via Entra Guest Invites: Taggart Tech

Dumb question: I don’t work directly in Entra much. Is there a way to query what tenants a user account is a part of? I found some posts that say not due to the required read access to the other potential tenants, but it seems like an admin should be able to see all tenants that their users have joined.

Yeah, but it’s gonna cost ya: Cross-tenant access activity workbook - Microsoft Entra ID | Microsoft Learn

1 Like

Thank you! Put it on my tab. :slight_smile:

This may come in handy: https://www.azuretenantlookup.com

1 Like

Oh I see the Premium P1 license requirement now. Now I get it. :frowning:

2 Likes