
Cybercriminals have made nearly 4.8 million attempts to exploit popular workplace platforms over the past year, using trusted services such as Zoom, Outlook, and OneDrive to disguise phishing attacks, malicious files and account takeover attempts.
New analysis by Kaspersky shows that Zoom was the most frequently impersonated workplace service during the period, accounting for 2.66 million attempted attacks. Outlook followed with 1.55 million, while OneDrive, Microsoft Excel, and Microsoft Teams recorded 197,030, 151,948, and 111,402 attempted attacks respectively.
Kaspersky recorded 4,781,846 attempted attacks involving content associated with widely used workplace platforms during the 12 months.
Downloaders accounted for the largest share of detected threats, with 2.73 million cases, while Trojans were the second-largest category, with 989,377 detections. Attackers can use these programs to steal information, monitor activity, gain remote access, or install additional malware. Exploits accounted for another 341,165 cases and can be used to exploit vulnerabilities in software and operating systems.
Beyond malicious files, attackers are also turning to legitimate workplace services to make phishing campaigns harder to detect.
One technique identified by Kaspersky involves Microsoft’s device authorization process. Rather than directing victims to a conventional fake login page, attackers provide a code and persuade users to enter it on a genuine Microsoft authentication page.
The approach can allow victims to unknowingly authorize an application controlled by attackers. While the user’s Microsoft password may not be exposed, the attackers can obtain an authorization token that could provide access to services such as email, OneDrive files or Teams messages.
The use of a genuine Microsoft page makes the technique particularly difficult to identify because checking the website address alone may not expose the scam.
Kaspersky also identified phishing campaigns posing as Google recruiters. In these cases, recipients were told their professional background had attracted the company’s attention and were invited to schedule an introductory call.
The messages were distributed through Google AppSheet, a legitimate Google service, with recipients eventually redirected to phishing pages designed to collect personal information and account credentials.
The campaign demonstrates how attackers can abuse legitimate platforms to give fraudulent messages an appearance of credibility, particularly when the lure involves an employment opportunity.
“Cybercriminals understand this context and may imitate exactly the tools people expect to encounter during the working day,” said Evgeny Kuskov, Lead Security Researcher at Kaspersky.
However, Kaspersky advises employees to scrutinize sender addresses and links before opening meeting invitations, shared files or account notifications. Users should also obtain workplace applications and updates only from trusted sources and be wary of documents requesting security settings to be disabled or additional software to be installed.
Businesses are also encouraged to use multi-factor authentication on critical accounts, provide regular phishing awareness training and independently verify unusual requests involving payments, document access or account permissions.
Additionally, Kaspersky recommends using security software to monitor devices for malicious files, phishing attempts and suspicious activity.
Download the FREE Kaspersky Next Enterprise Security Guide here to explore the complete framework for simplifying security operations and building cyber resilience.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to editorial@techtrendsmedia.co.ke



