Dangerous Email Scam Steals Office365 Credentials and Installs Malware – Be Alert!

A new email-based cyberattack tricks users into either giving away their Office365 login details or installing malware disguised as a Microsoft app. The attack uses trusted platforms like files.fm to appear legitimate and targets businesses and professionals using a double-threat strategy.
- Two-Pronged Attack: Victims receive emails pretending to warn about deleted documents. The links lead to files on files.fm, a trusted file-sharing site.
- Credential Theft via "Preview": Clicking "Preview" in the PDF redirects to a fake Microsoft login page. If users enter their login details, attackers steal them instantly.
- Malware via "Download": Clicking "Download" triggers installation of a fake Microsoft app named SecuredOneDrive.ClientSetup.exe, which actually deploys ConnectWise RAT, a Remote Access Trojan.
- Persistence Tricks: The malware sets itself to run at every startup by editing Windows Registry and creating system services, making it hard to remove.
- Remote Control: The malware connects to a remote server (screenconnect.com) allowing hackers to steal data, spy on users, and move within the network.
- Real Software Used for Harm: The ConnectWise Control tool—originally made for remote tech support—is being misused for cyberattacks.
This is a clear example of how hackers blend fake emails, trusted platforms, and legitimate-looking tools to launch powerful cyberattacks. Users must always double-check links, avoid downloading unknown files, and never enter login credentials on suspicious pages.
Net Protector Cyber Security urges all users and businesses to use anti-phishing protection, endpoint security, and enable multi-factor authentication (MFA) to stay protected from such multi-layered threats.
- Other (43)
- Ransomware (154)
- Events and News (27)
- Features (45)
- Security (487)
- Tips (79)
- Google (30)
- Achievements (11)
- Products (36)
- Activation (7)
- Dealers (1)
- Bank Phishing (53)
- Malware Alerts (235)
- Cyber Attack (303)
- Data Backup (13)
- Data Breach (132)
- Phishing (165)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (71)
- Android Security (78)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (71)
- Social Media (8)
- vulnerability (76)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (26)
- Uber (1)
- YouTube (1)
- Trojan (5)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (10)
- Mozilla (2)
- COVID-19 (5)
- Instagram (4)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (6)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (52)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (41)