Threat Group: Opportunistic and financially motivated actors targeting multiple sectors
Threat Type: Phishing and email infrastructure abuse
Exploited Vulnerabilities: Abuse of Microsoft 365 Exchange Online Direct Send feature; implicit trust of unauthenticated internal-looking emails; weak or unenforced SPF, DKIM, and DMARC
Malware Used: None required for initial access; follow-on payloads