Skip to main content
Abnormal Intelligence

Credential Phishing

Adobe Creative Cloud Phishing Attack Delivers Fake Microsoft 365 Login Page

Threat actors use Adobe Creative Cloud to host a phishing document with a link to a spoofed Microsoft 365 login page protected by a Cloudflare Turnstile.

December 30, 2024

Attack Target Summary

Attack Overview

Step 1: Email

The attack begins with an email containing a financially themed Adobe Creative Cloud-hosted document. This document appears to be legitimate and is shared from a verified source.

Attack Library Repo 7 16 Dec Image 1
  • Email passes SPF, DKIM, and DMARC checks.
  • Adobe document appears trustworthy due to legitimate branding.
  • Message encourages the user to view or interact with the hosted document.

The document contains a clickable link that directs the user to a phishing site. This site is designed to mimic a Microsoft 365 login page.

Attack Library Repo 7 16 Dec Image 2
  • Phishing link embedded inside the Adobe-hosted file.
  • Site mimics Microsoft's branding and login flow.
  • Target is prompted to enter email and password credentials.

Step 3: Cloudflare Turnstile + Phishing Page

Before reaching the login page, users must complete a Cloudflare Turnstile. This adds a false sense of legitimacy while preventing automated detection.

Attack Library Repo 7 16 Dec Image 3 A Attack Library Repo 7 16 Dec Image 3 B
  • Cloudflare Turnstile gate blocks security scanners.
  • Adds credibility to the phishing flow.
  • Helps ensure only real users land on the phishing page.

Step 4: Final Destination (Spoofed Microsoft Login)

Attack Library Threat Actors Exploit Docusign 6 Nov Portal

How Does This Attack Bypass Email Defenses?

This email attack bypasses traditional security solutions for several reasons, including:

  • The sender domain passed all authentication checks.
  • The link was hosted on Adobe Creative Cloud, a trusted service.
  • Cloudflare Turnstile blocked URL scanners from analyzing the final phishing destination.

How Did Abnormal Detect This Attack?

This attack was detected using AI and ML by analyzing various factors, including:

  • Behavioral anomalies from the sender and context.
  • Unusual URL patterns and cloud-hosted content.
  • Language analysis identifying financial urgency and deception.

By recognizing established normal behavior and detecting these abnormal indicators, a modern email security solution has the ability to prevent this attack from reaching inboxes.

Please note the exact detection mechanism from Abnormal Security's system might include proprietary techniques and methodologies not disclosed here.

Classification

Credential PhishingLink-basedExternal Party - Vendor/SupplierCredential Theft

Stop these attacks at your organization

See how Abnormal's behavioral AI detects the threats this digest covers — before they reach inboxes.