Phishing Attack Takes a Two-Step Approach to Leverage Legitimate Sites and Evade Detection

Stu Sjouwerman | Sep 6, 2024

Cookie Stealing Feature Phishing-As-a-ServiceAnalysis of a new phishing attack demonstrates how attackers may take a longer path to reach their malicious goals while staying “under the radar” of security products.

It would be pretty simple to create a phishing attack that sends its’ victims a brand-impersonated email with a link that takes you to an impersonated webpage that asks for credentials, personal details or credit card information.

But many of today’s security products will detect the impersonation immediately. So, if you’re a cybercriminal developing a cunning phishing scam, you need to find ways to avoid being detected – even if it means adding a few unnecessary steps.

And that’s exactly what we find in security vendor Perception Point’s latest analysis of a phishing attack that uses Microsoft Office Forms as an intermediate step in their phishing scam.  According to the analysis, the phishing email impersonates a well-known brand (such as Microsoft 365 below) with the first step being the clicking of a link within the email that points to an Office form.

Screenshot 2024-09-06 at 10.47.48 AM

The form is hosted on a legitimate web service, which helps the attack from being detected.

Screenshot 2024-09-06 at 10.48.54 AM

The target of that URL is an impersonated login page, designed to steal credentials:

Screenshot 2024-09-06 at 10.49.59 AM


At its core, this is just another credential stealing scam.  But it’s the specific execution that makes it interesting. By leveraging legitimate tools and websites as an added step in the attack, cybercriminals improve their odds that the scam will go undetected – that is unless the users have undergone security awareness training and are able to spot the scam.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.