SharePoint Phishing Returns With a COVID-19 Bait

Researchers at Area 1 Security have spotted a new wave of the notorious "PhishPoint" campaign. This iteration trades the earlier "Summer Bonus" lure for something timelier: supposed updates to corporate COVID-19 procedures. The renewed campaign, which reuses the infrastructure patterns of its predecessor, targets credentials by impersonating Microsoft SharePoint and login pages.

The attack is notable for its focus on upper-level management and executives. By aiming at high-value individuals, the operators increase their odds of reaching sensitive data or breaching internal networks. Messages are tailored per victim, embedding the target's email address and company name both in the message body and in the spoofed sender address.

BLOG-1435 Embedded Image - o0dSJ5

Fake Document Warnings and a Credible Facade

The phishing email mimics a standard work notice, warning the recipient that a SharePoint-hosted document was shared a week earlier and has not been opened. The perceived urgency is designed to push the target toward the embedded link. Compared with earlier PhishPoint messages, the formatting is improved, making the emails harder to dismiss at a glance.

BLOG-1435 Embedded Image - ym1Hb9

The infrastructure behind this campaign is as distributed as before. Area 1 Security counted roughly 100 unique sender addresses linked to this "COVID Requirements" effort. While the bulk of messages were sent from VPS providers—CrownCloud, HostWinds, and MGNHost—some traffic also came through SendGrid, a legitimate transactional email service whose domains are commonly whitelisted. Abusing a trusted provider allows the messages to pass basic authentication checks such as SPF, DKIM, and DMARC, which is why those protocols alone are insufficient against phishing.

This approach also sidesteps Secure Email Gateways that lean heavily on sender reputation. Since the emails carry no malicious payload and the URLs point to well-known domains, traditional defenses see nothing obviously wrong.

Cloud-Hosted Login Harvester

The link in each email, presented as an "Open" button, leads to a spoofed Microsoft login page hosted on AWS, Google's AppSpot, or Firebase. A sample URL includes the victim's corporate email address in the fragment, reinforcing the targeted nature of the campaign:

hxxps://x9n44x9nvc9nn9a4l9xa4cds[.]df[.]r[.]appspot[.]com/#[email protected]

BLOG-1435 Embedded Image - o0dSJ5

The spoofed page is nearly identical to Microsoft's legitimate login screen. The only visual tell is that the word "Outlook" appears in the title. Behind the scenes, the page's JavaScript mirrors the real login flow's behavior. A custom function pulls the victim's email from the URL and prepopulates the username field. That function contains a commented-out test string that includes "office1withemail", a breadcrumb that let researchers trace the code to a far larger body of phishing activity.

BLOG-1435 Embedded Image - FBTKeN

Pivoting on that string, Area 1 Security identified a substantial amount of phishing stretching back to at least April 2019. The campaigns in that cluster used varied lures, numerous hosting and VPS providers, and spanned multiple industries. The reuse of identical commented code across so many operations suggests a phishing kit rather than a single group. The JavaScript snippet below shows the structure of the credential-harvesting logic.

BLOG-1435 Embedded Image - sU0DxK

Post-Login Deception

If a victim submits a password, the page POSTs the credentials to a website on Microsoft Azure Web Sites, for example:

hxxps://fajal2a2l0jj0ccf2lf020jf[.]azurewebsites[.]net/handler[.]php

BLOG-1435 Embedded Image - Dvlv3o

After the submission, the page simulates a validation delay with a spinner next to the "Sign In" button. A few seconds later, it shows a generic error message claiming the password was incorrect—regardless of what was entered. That response makes the victim believe they simply mistyped their password and reduces suspicion. If the user clicks "Forgot my password", the link points to Microsoft's real password reset page, lending the scam a further layer of legitimacy.

BLOG-1435 Embedded Image - wWSSkD

Why Traditional Defenses Miss This

This campaign is difficult to stop for several reasons. The phishing URLs use legitimate, trusted domains from major cloud providers. The emails contain no malicious attachment or payload. And the messages themselves are well-constructed, passing basic authentication checks. In testing, Microsoft's own Office 365 email security failed to flag these messages.

As threat actors continue to alternate between VPS infrastructure and legitimate email delivery services, detection requires more than checking reputations. The sheer volume of activity and the reuse of infrastructure makes this an ongoing risk for individuals and enterprises alike.

Indicators of Compromise

Malicious Links:

  • hxxps://pidbbhitbt8007dtdhdlbhhp[.]azurewebsites[.]net/handler[.]php
  • hxxps://fajal2a2l0jj0ccf2lf020jf[.]azurewebsites[.]net/handler[.]php
  • hxxps://03ssrd3334phd00p4sh0s33drcorequemenxxkjw3450w1jklsha[.]s3-ap-southeast-1[.]amazonaws[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://owacovctctsttc00tscqcqts0c1tq[.]s3-ap-northeast-1[.]amazonaws[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://s3-ap-northeast-1[.]amazonaws[.]com/cxrequirement[.]sharepointeseugwpjlmahxedgkqsbjlzfgsn/index[.]html#@<targeted_company_domain>
  • hxxps://storage[.]cloud[.]google[.]com/owa9y0y90yh9y9ffy2990hfy90h[.]appspot[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://storage[.]cloud[.]google[.]com/sharedpoinnlinej27pj07jjppl7jp[.]appspot[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://storage[.]cloud[.]google[.]com/sharedpointoneqqnfcefoqi0e6cf[.]appspot[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://storage[.]cloud[.]google[.]com/sharedpointowauthdhljd1l0tdka0[.]appspot[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://storage[.]cloud[.]google[.]com/shonecov19dn1n1lnfflnbfblf1d[.]appspot[.]com/index[.]html#@<targeted_company_domain>
  • hxxps://tlook-off365-signin[.]web[.]app/#@<targeted_company_domain>
  • hxxps://x9n44x9nvc9nn9a4l9xa4cds[.]df[.]r[.]appspot[.]com/#@<targeted_company_domain>
  • hxxps://y02hh200222fyhffh90yhyhh[.]s3[.]us-east-2[.]amazonaws[.]com/index[.]html?eid=@<targeted_company_domain>
  • hxxp://d-nb[.]xyz/?e=@<targeted_company_domain>

Malicious Sites:

  • pidbbhitbt8007dtdhdlbhhp[.]azurewebsites[.]net
  • fajal2a2l0jj0ccf2lf020jf[.]azurewebsites[.]net
  • 03ssrd3334phd00p4sh0s33drcorequemenxxkjw3450w1jklsha[.]s3-ap-southeast-1[.]amazonaws[.]com
  • owacovctctsttc00tscqcqts0c1tq[.]s3-ap-northeast-1[.]amazonaws[.]com
  • y02hh200222fyhffh90yhyhh[.]s3[.]us-east-2[.]amazonaws[.]com
  • s3-ap-northeast-1[.]amazonaws[.]com/cxrequirement[.]sharepointeseugwpjlmahxedgkqsbjlzfgsn
  • storage[.]cloud[.]google[.]com/owa9y0y90yh9y9ffy2990hfy90h[.]appspot[.]com
  • storage[.]cloud[.]google[.]com/sharedpoinnlinej27pj07jjppl7jp[.]appspot[.]com
  • storage[.]cloud[.]google[.]com/sharedpointoneqqnfcefoqi0e6cf[.]appspot[.]com
  • storage[.]cloud[.]google[.]com/sharedpointowauthdhljd1l0tdka0[.]appspot[.]com
  • storage[.]cloud[.]google[.]com/shonecov19dn1n1lnfflnbfblf1d[.]appspot[.]com
  • x9n44x9nvc9nn9a4l9xa4cds[.]df[.]r[.]appspot[.]com
  • tlook-off365-signin[.]web[.]app
  • d-nb[.]xyz