Researchers Link Fake Giveaway Phishing to Google and Microsoft 365 Credential Theft
Medium · Help Net Security ·
Key points
- Malwarebytes and Unit 42 at Palo Alto Networks documented the campaign.
- Phishing operators use fake giveaways and spoofed sign-in pages.
- Targets include Google and Microsoft 365 users, plus Claude Max.
- Impact includes credential theft and account takeover.
- No CVE is linked; severity is medium.
Threat researchers at Malwarebytes and the Unit 42 team at Palo Alto Networks have documented a phishing operation that relies on bogus prize promotions to lure victims. The operators build counterfeit login screens, including browser-in-browser windows that mimic legitimate authentication prompts, then collect entered passwords and session data. The campaign is not tied to a software vulnerability; no CVE is associated with it.
The primary targets are people with Google accounts and Microsoft 365 accounts, though Anthropic's Claude Max is also named in the activity. Because the fake pages imitate Google sign-in and Microsoft 365 access, victims may not realize they are handing over credentials until account takeover occurs. The scheme has been tracked from 2022, with a June phase and a Sept. 23, 2026, report date.
Credential theft remains a direct path to account takeover, letting intruders read mail, files, and connected SaaS data. Browser-in-browser techniques make address bars and pop-up windows look trustworthy, so even cautious users can be fooled. For K-12 and government organizations, compromised Google or Microsoft 365 identities can expose student data, internal communications, and downstream applications.
The vendors involved—Malwarebytes, Palo Alto Networks, Google, Microsoft, and Anthropic—are not necessarily victims of a product flaw. Instead, the phishing operators abuse brand trust and familiar sign-in flows. The absence of a CVE means patching alone will not stop this; controls must focus on identity, user awareness, and detection.
Admins should watch for spikes in failed logins, impossible-travel alerts, new OAuth grants, and help-desk reports about giveaway messages. Any successful credential capture should trigger session revocation and password resets. Continued reporting from Malwarebytes and Unit 42 may reveal new lures or infrastructure.
What to do now
- Require phishing-resistant MFA for all Google Workspace and Microsoft 365 accounts, especially privileged and student-facing identities.
- Block or quarantine messages that mention prize promotions, giveaways, or unexpected account verification links.
- Monitor and review OAuth consent grants for Google, Microsoft 365, and SaaS tools such as Claude Max; revoke suspicious tokens immediately.
- Enable conditional access and impossible-travel alerts, then automate session revocation and password reset on suspected credential capture.
- Train staff and students to inspect browser-in-browser prompts and to navigate directly to official sign-in pages instead of clicking links.
- Add lookalike-domain detection for Google, Microsoft, and Anthropic brands, and report new phishing infrastructure to security teams.
Original source
Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.