$ techbeacon▋
Phishing

Phishing Campaign Targets U.S. Eastern Business Hours Using Microsoft 365 Direct Send

Phishing Campaign Targets U.S. Eastern Business Hours Using Microsoft 365 Direct Send

Security researchers at KnowBe4 have uncovered a phishing operation that deliberately aligns its malicious email deliveries with standard U.S. Eastern business hours, exploiting Microsoft 365’s Direct Send feature to reach corporate inboxes.

Direct Send allows an authenticated Microsoft 365 account to transmit email to any recipient without routing through the service's outbound spam filters, a capability intended for legitimate internal communications and automated notifications. Because the messages bypass certain protective layers, they can appear more authentic to recipients and evade some conventional anti‑phishing tools.

The investigation revealed a consistent pattern: bulk messages are dispatched between 8 a.m. and 5 p.m. Eastern Time, coinciding with the typical workday of many North American enterprises. The campaign leverages compromised or newly created Microsoft 365 accounts to send the emails, which contain links or attachments designed to harvest credentials or deploy malware.

Timing the attacks for peak office hours increases the likelihood that recipients will engage with the messages amid a high‑volume inbox flow. Employees are often less cautious when handling routine‑looking emails during a busy workday, creating an optimal window for social‑engineering success.

The tactic reflects a broader shift in phishing strategies toward more sophisticated delivery methods. As Microsoft 365 continues to dominate the corporate productivity market, threat actors are adapting their approaches to exploit platform‑specific features. Prior incidents have shown attackers abusing legitimate services to mask malicious intent, and the current campaign adds Direct Send to that growing list.

Experts advise organizations to reinforce existing defenses by enabling multi‑factor authentication, tightening mailbox access policies, and monitoring for anomalous outbound email activity. User education remains critical; staff should be reminded to verify unexpected links or attachments, even when messages appear to originate from internal accounts.

Looking ahead, researchers expect similar timing‑based campaigns to emerge in other regions as attackers refine their operational models. Continuous threat‑intelligence sharing and proactive configuration reviews will be essential for enterprises seeking to mitigate the risk posed by these targeted phishing attempts.

Deepak Chandra Meena — Deepak covers the dark web and underground hacking forums, reporting on marketplace activity and access broker listings. Monitors Tor-based forums and encrypted leak channels.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related