AI-Driven Phishing Attack Compromises Microsoft Dynamics 365 Credentials in ‘Project Deception’

Security experts at Perception Point have uncovered a complex phishing scheme known as “Uncle Scam.” In this campaign, cybercriminals use AI to impersonate U.S. government agencies, sending fake tender invitations to a wide range of American businesses.

The attackers employ sophisticated methods, including interactive tools and large language models (LLMs), to craft highly realistic phishing emails. The scam starts with an email, seemingly from the General Services Administration (GSA), inviting recipients to bid on a federal project. The email contains a link that directs users to a counterfeit GSA website, meticulously designed to resemble the genuine site. This bogus site includes navigation links and search functions that lead to actual GSA pages, adding to its credibility and making it harder for users to detect the fraud.

When users click on the “Register For RFQ” button, they are taken to a CAPTCHA page, a tactic used by attackers to bypass automated security systems. After users enter their details, the attackers capture their credentials.

The fraudulent website closely mirrors the legitimate one, which helps convince visitors of its authenticity.

The attackers also added a detailed pop-up guide that walks users through the registration process for the RFQ, requiring multiple clicks before reaching the fake login page.

Perception Point shared with Cyber Security News that “When the user clicks the link, they are redirected to a spoofed GSA page, complete with a domain mimicking the legitimate GSA domain (www.gsa.gov). The phishing site is nearly identical to the legitimate site, assuaging visitors of its supposed authenticity.” This attention to detail not only boosts the site’s credibility but also makes it harder for users to realize they are on a malicious site.

Exploitation of Microsoft’s Dynamics 365 Marketing Platform

A key element of this campaign is the misuse of Microsoft’s Dynamics 365 Marketing platform. The attackers exploit the domain dyn365mktg.com to create subdomains and send malicious emails.

Because this domain is associated with Microsoft, phishing emails are more likely to bypass spam filters and land in recipients’ inboxes, enhancing the campaign’s success rate.

This domain is pre-authenticated by Microsoft, adhering to DKIM and SPF protocols, which further increases the chances of these emails evading spam filters and reaching the intended targets.

The built-in credibility of this domain, due to its connection with a trusted marketing platform, makes emails sent from it appear more legitimate, thereby increasing the effectiveness of the phishing campaign.

Perception Point researchers identified two variations of the phishing attack, both utilizing LLMs. These models enable attackers to generate sophisticated and contextually accurate emails on a large scale. The emails impersonate various U.S. government departments, maintaining a professional tone and including department-specific details.

Protection Strategies

To guard against such advanced phishing attacks, organizations should:

  1. Verify the Sender’s Email: Carefully check the sender’s email address for authenticity.
  2. Inspect Links Before Clicking: Hover over links to see the actual URL.
  3. Watch for Errors: Be alert for grammatical mistakes or unusual wording.
  4. Utilize Advanced Detection Tools: Deploy AI-driven, multi-layered security solutions.
  5. Train Employees: Educate staff on recognizing phishing emails and verifying unsolicited communications.
  6. Trust Your Instincts: Be wary of offers that seem unusually good and verify their legitimacy through trusted sources.

More Articles & Posts