Attackers ran a credential-theft campaign that impersonated Office 365 password-expiration notices to target CEOs and other senior executives across manufacturing, real estate, finance, government, and technology organizations. The operation used more than 300 compromised URLs and reused hijacked infrastructure and stolen credentials to reach victims in the United States, Japan, the UK, Canada, Australia, and parts of Europe, with lures tailored to high-value corporate personnel.
Researchers found the campaign relied on a commercially sold Office 365 phishing kit identified as version 4, which included credential validation, anti-analysis blocklists, bot detection, and license-verification features. Misconfigured phishing pages exposed kit files and logs containing stolen victim data and redirection details, while test traffic linked to IP addresses in Morocco offered possible attribution clues; the emails were commonly sent through FireVPS RDP infrastructure, and underground forum activity showed active sales of both the phishing kit and compromised executive account credentials.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Researchers said they had tracked the campaign since May 2020. The operation used fake Office 365 password-expiration emails and compromised URLs to target executives.
A second version of the phishing kit was reportedly released 15 days after the first version. This indicates active development of the kit in mid-2019.
The phishing kit used in the campaign was reportedly first released on July 4, 2019. Trend Micro identified the later observed toolkit as version 4 of this commercially sold kit.
Trend Micro said the related phishing activity was evolving since 2019, preceding the campaign period it later tracked directly. The activity centered on fake Office 365 lures targeting senior corporate personnel.
Trend Micro notified FireVPS that its VPS and RDP services were being used to send phishing emails in the campaign. The emails were commonly sent through FireVPS remote desktop infrastructure before transiting Microsoft Outlook SMTP infrastructure.
By September, URL prefixes used in the campaign shifted from "sg" to alternatives such as "pl," "00," and "ag." This marked another observable evolution in the phishing infrastructure.
By August, phishing landing pages in the campaign began including the keyword "OfficeV4." This reflected a change in the infrastructure or kit branding used in the operation.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.