Attackers ran an Office 365 credential-harvesting campaign that sent "missed voice message" lures through legitimate University of Oxford SMTP servers, helping the emails bypass trust-based defenses and appear credible to recipients. The operation primarily targeted organizations in Europe, with additional activity observed in Asia and the Middle East, and focused on stealing Microsoft 365 credentials through convincing fake login pages.
The attack chain used multiple trusted and compromised services to evade detection, including Samsung Canada’s Adobe Campaign open redirect capability and compromised WordPress sites that forwarded victims to obfuscated phishing pages. Researchers said the operators continuously rotated redirect infrastructure, created per-victim directories, and used JavaScript-generated, XOR-obfuscated HTML to make the phishing kit harder to detect and analyze; Adobe and Samsung were reported as abused infrastructure providers rather than victims of a software exploit.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
The second redirect stage used compromised WordPress sites that only redirected when a specific fragment pattern was present, concealing the abuse from casual visits by site owners.
Attackers used an Adobe Campaign redirection mechanism on Samsung Canada infrastructure by modifying parameters in a legitimate campaign URL to send victims to attacker-controlled destinations.
The campaign sent phishing emails through legitimate University of Oxford SMTP infrastructure using generated addresses on Oxford subdomains, helping messages pass sender reputation checks.
Check Point Research detected an Office 365 phishing campaign in early April 2020. The operation used missed-voice-message lures and targeted organizations primarily in Europe, with additional activity in Asia and the Middle East.
According to urlscan, the domain t.info.samsungusa.com had been used for phishing-related redirects prior to the campaign described in the report.
The report notes that Adobe Campaign open redirects had been discovered on Adobe-owned domains before this campaign, establishing a known abuse pattern for the redirect mechanism.
The attackers later broadened the operation to multiple compromised WordPress sites hosting similar redirect paths and altered previously constant URL parameters to evade pattern-based detection.
The operators later changed email links to use the subdomain t-email1.ottawashowers.ca with an /r/ path to mimic Adobe Campaign redirects and reduce dependence on Samsung infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.