Hackers Abuse Microsoft 365 Exchange Direct Send to Bypass Content Filters and Harvest Sensitive Data
The Direct Send feature of Microsoft 365 Exchange Online, originally intended to facilitate email communication for legacy devices and applications without requiring authentication, has been identified as a vector for sophisticated phishing and business…
The Direct Send feature of Microsoft 365 Exchange Online, originally intended to facilitate email communication for legacy devices and applications without requiring authentication, has been identified as a vector for sophisticated phishing and business email compromise (BEC) attacks.
Direct Send is designed to allow multifunction printers, scanners, and older line-of-business applications to send emails by bypassing stringent authentication and security checks . This operational convenience has been exploited by cybercriminals to circumvent standard content filters and domain verification protocols.
Investigations have revealed an increase in malicious campaigns leveraging Direct Send to distribute fraudulent emails that appear to come from trusted internal sources. Threat actors are mimicking legitimate device traffic, sending unauthenticated emails that impersonate executives, IT help desks, and internal users. These messages often include business-themed social engineering tactics, such as task approvals and payment prompts, to manipulate recipients into revealing credentials or sensitive data.
Cisco Talos analysts have documented heightened activity in phishing and BEC campaigns utilizing Direct Send. Security researchers from various organizations, including Varonis, Abnormal Security, Ironscales, Proofpoint, Barracuda, and Mimecast, have confirmed similar findings, indicating ongoing exploitation targeting corporations.
This operational convenience has been exploited by cybercriminals to circumvent standard content filters and domain verification protocols.
The attacks exploit the trust delegated from the Exchange infrastructure, reducing scrutiny on message payloads and enabling circumvention of essential sender verification mechanisms. The exploitation involves bypassing three key email authentication protocols: DomainKeys-Identified Mail (DKIM), Sender Policy Framework (SPF), and Domain-based Message Authentication, Reporting, and Conformance (DMARC).
Normally, these protocols verify message authenticity through cryptographic signatures, authorized IP ranges, and policy enforcement. However, Direct Send allows spoofed messages to bypass these checks, reaching recipients unchallenged. Attackers have embedded QR codes within PDFs and crafted empty-body messages with obfuscated attachments to evade traditional content filters and direct victims to credential harvesting sites.
In response, Microsoft has launched a Public Preview of the RejectDirectSend control and announced future updates, including Direct Send-specific usage reports and a default-off configuration for new tenants. To mitigate risks, organizations can disable Direct Send using the command Set-OrganizationConfig -RejectDirectSend $true after verifying legitimate mail flows. Additional measures include migrating devices to authenticated SMTP submission on port 587 and implementing strict IP restrictions for devices unable to authenticate.
Based on reporting by Cyber Security News.
