APAC Cybersecurity at SMBtech

Attackers Exploit Real Microsoft Login Pages And Split-Click Buttons In New Wave Of Phishing Campaigns

Surprisingly Useful AI Article Enhancements

Security researchers at Barracuda have identified a series of phishing campaigns that use real Microsoft login pages, weaponised PDF attachments and a rare “split-click” technique to steal session tokens and bypass conventional email defences.

The findings, published in Barracuda’s Email Threat Radar for June 2026, also flag a broader shift in attacker behaviour, with some campaigns moving away from credential theft and toward direct malware delivery using obfuscated scripts hidden inside fake invoices.

Real Microsoft Login Pages Used To Intercept Session Tokens

One of the campaigns identified by Barracuda researchers uses a genuine Microsoft login page rather than a spoofed imitation to intercept users’ session tokens and access permissions.

Victims receive a legitimate-looking warning that their inbox is nearly full, accompanied by a calendar invite to a meeting with Microsoft security. The meeting is not referenced in the main body of the email, which instead features a button prompting users to release emails that have been held back.

The button is a calendar invite that links to a real Microsoft login page, but one routed through the Tycoon 2FA phishing-as-a-service platform. The attackers have registered their own Microsoft account and are directing victims to enter their credentials into it.

Once the user enters their credentials and receives a session token, that token is captured by the attackers. In a supplementary step, victims are asked to enter their credentials again, this time into a fake page, allowing the attackers to also steal their password.

The approach differs from conventional phishing attacks, which typically rely on imitation pages. By using a genuine Microsoft domain, the campaign bypasses many security checks and can deceive employees trained to spot spoofed URLs.

The capture of session tokens and OAuth permissions gives the attackers immediate and persistent access to victims’ email, online files and linked Microsoft 365 services.

Calendar invites are a rarely monitored attack vector, making them effective for bypassing traditional email defences.

The weaponised OAuth authorisation stage involves the victim being redirected to a legitimate Microsoft OAuth authorisation registered by the attackers. Researchers observed a malicious application registered in Microsoft Entra that requests permissions scoped to Outlook and includes “offline_access,” which grants a refresh token for persistent access.

The attackers’ infrastructure also supports Proof Key for Code Exchange (PKCE), making the OAuth flow appear consistent with modern authentication standards.

PDF Attachments Weaponised For Device Code Phishing

In a separate campaign, attackers have removed suspicious links from the main body of phishing emails and placed them inside PDF attachments, where they are less likely to be detected by URL scanners.

The emails ask recipients to open an attachment relating to either a compliance or payment issue. A link embedded in the PDF takes users to a fake device authentication flow that captures their credentials and business email address.

Unlike previously reported device code phishing attacks that used real Microsoft APIs, this campaign generates fake device codes locally in the browser, mimicking the legitimate device code authorisation flow that victims will recognise from linking apps and devices to their Microsoft accounts.

The use of CAPTCHA blocks automated scanning and sandbox detection, ensuring only real users reach the phishing stage.

The campaign is also notable for its short-lived infrastructure. The phishing pages are self-expiring and disappear automatically after a set time, which limits forensic analysis and post-event detection.

Split-Click Technique Gives One Button Two Outcomes

Barracuda researchers also encountered an email attack featuring a single button that behaves differently depending on where the user clicks.

The email warns users that their mailbox is full and includes a “Resolve Issue” button. Clicking the top half of the button opens a legitimate Microsoft page, while clicking the bottom half triggers a malicious redirect.

The malicious option opens a blob URL, which is a browser-generated web page, that redirects via a link to a phishing page belonging to the Sneaky 2FA phishing-as-a-service platform. This is where the attackers capture credentials and other sensitive information.

The split-click interaction is a rarely seen technique. It is designed to evade automated link analysis and ensure testing tools can only see the safe version.

Blob URLs are generated dynamically by the browser and are harder to inspect or block using traditional tools.

Phishing Campaigns Shift Toward Malware Delivery

Beyond credential theft, researchers uncovered campaigns in which phishing emails are being used to deliver malware directly.

In one attack, a typical fake invoice download turns out to be a malicious JavaScript file. The attack email appears to be a routine invoice notification, presenting victims with a link to a fake document named “Invoice.pdf.” However, instead of delivering an invoice, the link triggers the download of a malicious JavaScript file.

The script hides its malicious code in the fake document using steganography and obfuscation. Once executed, it can load additional malware, gather system information, establish persistence and communicate with attacker-controlled infrastructure.

Fileless Malware Delivered Through Impersonation

In another campaign, attackers impersonate the Social Security Administration to distribute a malicious JavaScript file disguised as a payment receipt PDF.

The heavily obfuscated script reconstructs a hidden URL, retrieves a second-stage payload from a remote server and executes it directly in memory using Windows ActiveX components.

By avoiding file drops and leveraging in-memory execution, the malware reduces its visibility to traditional security tools and can be used to deliver credential stealers, banking trojans or other malicious payloads.

Multi-Step Redirection Adds Layers Of Deception

Researchers also observed an attack in which an HTML file led the recipient to a fake OneDrive page, which in turn directed them to an Excel login. This kind of multi-step redirection improves credential theft success rates by hiding malicious intent behind multiple layers.

Defending Against The New Techniques

Barracuda’s research highlights the need for organisations to protect identities and session tokens, not just passwords, and to extend detection beyond email to calendar invites, attachments and login flows.

The company recommends using behavioural detection to catch evasive attacks, investing in attachment and endpoint protection for fileless and embedded threats and enabling rapid response capabilities, as many of these attacks are short-lived and difficult to trace.

Organisations should also update training to reflect real-world phishing techniques that are now bypassing traditional controls.

Last Updated on August 15, 2026 by Nick Ross

Surprisingly Useful AI Article Enhancements

Sign-up to the SMBtech Daily Newsletter

We will not spam you. You can easily unsubscribe any time. Read our privacy policy.