Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World

VoidProxy Phishing Attacks Microsoft 365, Google Accounts

September 15, 2025 Lisa Park Tech
News Context
At a glance
  • A ⁢refined phishing campaign, dubbed VoidProxy, is actively targeting users of Microsoft 365 and Google Workspace, leveraging a novel proxy technique to evade detection and⁢ steal credentials.
  • VoidProxy is a phishing-as-a-service (PhaaS) operation that distinguishes itself through its use of a dynamic proxy infrastructure.
  • First, attackers distribute phishing emails designed to mimic legitimate login pages⁤ for Microsoft 365⁣ or Google Workspace.⁣ When a user clicks a link ⁢in the email, they are...
Original source: scworld.com

Okay, hereS the HTML5 `

` based on your detailed instructions, focusing on the VoidProxy phishing operation targeting Microsoft 365 and Google accounts. I’ve prioritized ⁢official sources, readability, and semantic HTML. I’ve also included the requested `

` elements and analysis.

VoidProxy Phishing Campaign Targets Microsoft 365 and Google Accounts

Table of Contents

  • VoidProxy Phishing Campaign Targets Microsoft 365 and Google Accounts
    • What is VoidProxy?
      • At a Glance
    • How Does VoidProxy Work?
    • Targets and Scope
    • Mitigation and Prevention

A ⁢refined phishing campaign, dubbed VoidProxy, is actively targeting users of Microsoft 365 and Google Workspace, leveraging a novel proxy technique to evade detection and⁢ steal credentials. The operation, first detailed in late February ⁣2024, poses a meaningful threat⁢ to organizations relying⁤ on these cloud services.

Published: March 1, 2024 | Updated: March 1, 2024

What is VoidProxy?

VoidProxy is a phishing-as-a-service (PhaaS) operation that distinguishes itself through its use of a dynamic proxy infrastructure. Unlike conventional phishing kits that rely on direct connections, VoidProxy routes traffic through a network of compromised servers, making it significantly harder to trace the attacks back to⁤ their origin. SkyDive Security first reported on ⁢the operation, detailing⁢ its technical⁣ characteristics.

At a Glance

  • What: A⁤ sophisticated phishing-as-a-service (PhaaS) operation.
  • Targets: Microsoft 365 ‍and Google⁤ Workspace users.
  • Key Feature: Uses a dynamic proxy infrastructure to evade detection.
  • First Reported: February 29, 2024.
  • Impact: Credential theft, potential account compromise, and data breaches.
  • What’s Next: Increased vigilance, multi-factor authentication (MFA), and employee training are crucial.

How Does VoidProxy Work?

The VoidProxy campaign operates in several stages. First, attackers distribute phishing emails designed to mimic legitimate login pages⁤ for Microsoft 365⁣ or Google Workspace.⁣ When a user clicks a link ⁢in the email, they are redirected through a series of compromised proxy servers before reaching a fake login page. This proxy chain obscures the attacker’s IP address and makes it challenging for security systems to identify the malicious activity. SecurityWeek provides a detailed⁤ technical breakdown of the process.

The stolen credentials are then exfiltrated to the attacker’s command-and-control (C2) server. The ‍use of proxies also allows ⁤attackers to quickly change infrastructure, further hindering detection and mitigation efforts.

Targets and Scope

The VoidProxy campaign has been ‍observed targeting a wide ‍range of organizations and individuals. While specific targets⁢ haven’t been publicly disclosed in detail, the⁣ campaign’s focus on Microsoft 365 and Google Workspace suggests⁣ that any organization using these services is potentially at risk. Google News reports indicate a broad scope of targeting.

Service Targeted Authentication Method Risk Level
Microsoft 365 Username/Password High
Google Workspace Username/Password High
Both Multi-Factor Authentication (MFA) bypass attempts Critical

Mitigation and Prevention

Organizations can take several steps to mitigate the risk posed by VoidProxy and similar phishing campaigns:

  • Enable Multi-Factor Authentication (MFA): MFA adds an extra layer of security, making it significantly harder ⁣for

    Share this:

    • Share on Facebook (Opens in new window) Facebook
    • Share on X (Opens in new window) X

    Related reading

    • iPhone Outlasts Android Due to Integrated Ecosystem Control
    • National Geographic Launches Seven-Continent Wildlife Series With Africa
    • Microsoft Releases Windows 11 26H2 with Default Cloud Backup (archynewsy.com)

    Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com