🟠 High  |  Source: The Register — Security


Russian state-sponsored threat actors have adapted their ‘half-click’ phishing technique — previously used against Zimbra — to target Microsoft Outlook users. Opening a malicious email deploys a browser implant that persists even after the victim changes their password or rebuilds their device. This makes the attack particularly dangerous as traditional remediation steps are insufficient to remove the compromise.

Security Architect’s Take: Review conditional access policies to enforce device compliance and phishing-resistant MFA (e.g. FIDO2) across your Microsoft 365 estate, as credential resets alone will not remediate this implant. Additionally, audit browser extension controls and consider deploying endpoint detection capable of identifying persistent browser-level implants.

Original advisory: Russian spies take their half-click email attack from Zimbra to Outlook