BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: This Message Was Sent by Microsoft: Turning Microsof
 t Apps\n   into our Phishing Platform\n   Tags: DEF CON Official Talk | De
 mo 💻 | Exploit 🪲\n   When: Sunday\, Aug 9\, 10:00 - 10:59 PDT\n   Wh
 ere: LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-2 - [1]Map\n\n   De
 scription:\n\n   Last DEF CON\, we stole cleartext credentials directly fr
 om the real\n   Microsoft login page. This year\, we take it a step furthe
 r by making\n   Microsoft deliver our phishing emails!\n\n   We've all see
 n threat actors abuse built-in email notifications from\n   legitimate Saa
 S platforms to send phishing links from trusted domains\,\n   bypassing em
 ail security solutions. But in most cases\, they only\n   control a small 
 portion of the email content\, making the end result\n   far from convinci
 ng.\n\n   While the execution of these examples has mostly been fairly poo
 r and\n   limited in complexity so far\, the idea of making a legitimate\n
    application deliver your phishing payload did intrigue me. So I\n   sta
 rted digging for more advanced ways to push this concept further\,\n   loo
 king for techniques that would allow taking over the majority (or\n   some
 times the entirety) of the email content.\n\n   In this talk\, I'll presen
 t several novel techniques to inject custom\n   phishing pretexts into ema
 ils sent by multiple first-party Microsoft\n   services\, taking advantage
  of their trusted email addresses and domain\n   reputation.\n\n   These e
 mails seem so legitimate that even seasoned IT and security\n   profession
 als would trust them (and we have the proof from our\n   assessments to ba
 ck this up). After all\, who doesn't trust Microsoft?\n   😉\n\n     * D
 EFCON33 - Turning Microsoft's Login Page into our Phishing\n       Infrast
 ructure\n\n         * https://www.youtube.com/watch?v=z6GJqrkL0S0\n\n     
 * GraphSpy\n\n         * https://github.com/RedByte1337/GraphSpy\n\n     *
  SharePoint SendEmail API retirement\n\n         * https://support.microso
 ft.com/en-us/office/retirement-of-the-sharepoint-sendemail-api-b35bbab1-7d
 09-455f-8737-c2de63fe0821\n\n   SpeakerBio:  Keanu "RedByte" Nys\, Spotit\
 n\n   Keanu Nys (aka RedByte) is an information security researcher from\n
    Belgium\, and currently leads Spotit's offensive security team. While\n
    he has a passion for all offensive cybersecurity topics\, he mostly\n  
  specializes in Active Directory\, Microsoft Entra ID (Azure AD)\, and\n  
  Social Engineering.\n\n   He is the author of the Microsoft 365 and Entra
  attack toolkit\n   GraphSpy. Additionally\, Keanu is the trainer for the 
 Certified Azure\n   Red Team Expert (CARTE) bootcamps at Altered Security\
 , and has given\n   talks\, workshops and trainings at conferences like DE
 F CON\, Blackhat\n   USA\, and BruCON.\n\n   '\n\n   1. #LVCCW_Level1_Hall
 3\n\n\n
DTEND:20260809T175900Z
DTSTART:20260809T170000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 1007 (Main Track 2) and DCTV-
 2
SUMMARY:This Message Was Sent by Microsoft: Turning Microsoft Apps into our
  Phishing Platform
END:VEVENT
END:VCALENDAR
