Entra Phishing

By GAYINT Staff

This may come as a shock to some of you but we here at GAYINT actually do play well with others. Case in point: We have been working with some other fedi nerds on an ongoing phishing campaign targeting M365 tenants from other M365 tenants. There are more details over on Taggart's blog.

But here are some things to hunt on while you read that post:

IndicatorTypeDescription
invites@microsoft[.]comEmailSender address for Entra invites
invited you to access applications within their organizationStringEmail Subject substring to search for Guest User invitations
CloudSyncStringAttacker Tenant Name
Advanced Suite ServicesStringAttacker Tenant Name
TenantHubStringAttacker Tenant Name
Unified Workspace TeamStringAttacker Tenant Name
Advanced Suite ServicesStringAttacker Tenant Name
x44xfqf.onmicrosoft[.]comDomainAttacker Tenant Domain
woodedlif.onmicrosoft[.]comDomainAttacker Tenant Domain
xeyi1ba.onmicrosoft[.]comDomainAttacker Tenant Domain
x44xfgf.onmicrosoft[.]comDomainAttacker Tenant Domain



Updated: 14 November 2025