Static Web Apps, an Azure service, is being used by cybercriminals to phish Microsoft 365 subscribers.
Custom branding for web applications and web hosting for static material like HTML, CSS, JavaScript, or graphics are two capabilities of Static Web Apps that may be easily misused.
Researchers now claim that threat actors have made advantage of these characteristics to host static landing phishing sites. With the corporate logo and the Single SignOn (SSO) option that collects Office 365, Outlook, or other credentials, these landing pages seem virtually similar to legitimate Microsoft services.
The use of cunning strategies
Azure Static Web Apps are a “great technique,” according to BleepingComputer, since the *.1.azurestticapps.net wildcard TLS certificate gives each landing page its own secure page padlock in the URL bar.
TLS certificates like this one may fool even the most sceptical of victims.
The phoney Microsoft TLS certificate also makes the landing pages excellent for targeting users on other platforms and email providers, since these victims might also be tricked by the bogus security guarantee of the actual Microsoft certificate.
A common first step for someone who suspects a phishing attempt is to verify the URL they’re being directed to. Many will be tricked by the azurestticapps.net domain and believe that the identity is real while using Azure Static Web Apps, according to this report.
Static Web Apps in Azure Build and deploy full stack web applications to Azure from a code repository using Microsoft’s service.
Azure Functions connectivity, GitHub and Azure DevOps integration, globally distributed static content and free, automatically renewed SSL certificates are just a few of the characteristics that make it a great option for those that need to store static material like HTML, CSS, JavaScript and photos.