Hackers Abuse Outlook Groups and Microsoft 365 Collaboration Features for Phishing Attacks

Cybersecurity researchers have uncovered a sophisticated new phishing tactic that leverages trusted Microsoft 365 collaboration tools.

According to the Fortra Intelligence and Research Experts (FIRE), threat actors are increasingly abusing Outlook Groups and shared productivity features to disguise malicious activities as routine business operations.

Instead of relying on traditional spoofed emails or obvious malicious attachments, hackers are integrating their attacks directly into familiar corporate workflows.

When users interact with what appears to be a standard group addition, internal update, calendar invite, or shared resource, they are unknowingly guided toward actions that compromise enterprise security.

Once a user engages by signing in, downloading a file, or accepting an invite, the attack can result in credential theft, malware delivery, token capture, or severe data exposure across the network.

Outlook Groups Fuel Phishing

Modern phishing campaigns are rapidly moving away from easily detectable fake invoices and clumsily spoofed brands. Instead, cybercriminals are borrowing legitimacy directly from Microsoft’s own cloud infrastructure.

The attack begins when a threat actor creates or compromises a Microsoft 365 group and intentionally gives it a trustworthy name such as “IT Support,” “HR Updates,” “Leadership Briefing,” or “Finance Review.”

Outlook Groups Fuel Phishing (Source: fortra)
Outlook Groups Fuel Phishing (Source: fortra)

The attacker then invites the target into this group. Because the invitation originates from a legitimate Microsoft cloud service, the initial welcome email typically bypasses standard security filters and lands directly in the user’s inbox looking completely healthy and harmless.

Once the victim is added to the group, the attacker utilizes shared files, group mailboxes, and calendar invitations to deliver the actual malicious payload.

A core component of this strategy is Calendar Phishing, also known as “CalPhishing.” By sending malicious .ics calendar invites, hackers successfully move the threat out of the email inbox and into the user’s daily corporate schedule.

Outlook Groups Fuel Phishing (Source: fortra)
Outlook Groups Fuel Phishing (Source: fortra)

These calendar invites are often disguised as mandatory training sessions, project meetings, or urgent payroll reviews.

The true danger of CalPhishing lies in its persistence. Even if a user ignores or deletes the initial email notification, the calendar event remains active.

Scheduled reminders will continually prompt the user to join the meeting or review the attached documents, applying psychological pressure over time.

Furthermore, attackers utilize the group’s shared file space to host malicious documents containing fake support processes, QR codes, macro lures, or credential-harvesting links.

Because these files are accessed through a trusted Microsoft collaboration environment, victims are far more likely to lower their guard.

According to Fortra research, defending against this evolving threat requires security teams to look well beyond initial email delivery.

Relying solely on standard email filtering is insufficient because the attack spans multiple collaboration surfaces. Security professionals must achieve cross-surface visibility to track the entire attack chain.

Incident response investigations must determine who created the group, which internal users were added, what files were uploaded to the shared space, and whether any lingering calendar artifacts remain after the initial email is removed.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories