RingCentral Phishing-as-a-Service Campaign Bypasses Microsoft 365 Security

www.news4hackers.com-ringcentral-phishing-as-a-service-campaign-bypasses-microsoft-365-security-ringcentral-phishing-as-a-service-campaign-bypasses-microsoft-365-security

Threat actors are mimicking RingCentral alerts to gain unauthorized access to Microsoft 365 business environments, exploiting OAuth application permissions and adversary-in-the-middle infrastructure to circumvent multi-factor authentication protocols.

Technical Overview

Researchers have detected the campaign utilizing adversary-in-the-middle phishing kits to bypass corporate multi-factor authentication defenses seamlessly. The operation initiates when targets receive fabricated notifications resembling RingCentral missed call alerts, voicemail updates, or urgent business document requests. These messages originate from either compromised organizational accounts or spoofed systems engineered to pass basic validation checks.

Attack Vector and Tactics

Upon clicking the embedded link, users are routed through multiple redirection stages, including automated CAPTCHA challenges designed to evade security scanners and sandbox detection mechanisms. The campaign’s technical architecture combines malicious Microsoft 365 OAuth applications with advanced adversary-in-the-middle infrastructure.

OAuth Exploitation and Adversary-in-the-Middle Infrastructure

Victims are presented with a deceptive Microsoft consent prompt requesting permissions for a counterfeit enterprise application mimicking RingCentral or affiliated services. By seeking seemingly innocuous permissions such as user profile access and openid authentication, the malicious application avoids triggering standard security alerts while establishing a persistent presence within the victim’s tenant.

Operational Mechanics

Simultaneously, threat actors deploy the Tycoon phishing-as-a-service framework to operate a reverse proxy between the target user and the legitimate Microsoft authentication server. When credentials are entered and multi-factor authentication is completed, the reverse proxy intercepts active session cookies and OAuth access tokens in real time. This enables attackers to bypass two-factor security measures entirely without requiring password cracking or repeated authentication prompts.

Impact and Consequences

Compromised accounts provide attackers with unrestricted access to corporate inboxes, internal Microsoft Teams communications, and sensitive documents stored across SharePoint and OneDrive. Security analysts report that breached accounts are frequently used as launch points for internal spear-phishing operations, vendor infiltration schemes, and financial fraud targeting global partner organizations.

“As cybercriminals increasingly repurpose trusted enterprise tools as attack vectors, organizations must apply stringent cryptographic scrutiny to all external authentication requests.”

Mitigation Strategies

Mitigating this threat demands enterprise security teams adopt measures beyond conventional filtering and employee training. Administrators must enforce stricter tenant configuration policies by limiting end-user consent for third-party OAuth applications, implementing rigorous admin approval workflows, and deploying conditional access rules based on device compliance and geographic anomalies.


Blog Image

About Author

en_USEnglish