For years, enterprise phishing defense strategies have largely focused on one familiar threat vector: suspicious emails arriving in employee inboxes. Security teams built detection logic around malicious attachments, suspicious links, spoofed sender domains, and increasingly sophisticated business email compromise campaigns.

But threat actors are quietly shifting away from traditional email-centric delivery models.

Recent threat intelligence research from Fortra highlights a growing trend where attackers abuse legitimate collaboration features inside Microsoft 365 to disguise phishing campaigns as ordinary workplace activity. Rather than relying solely on a single malicious email, adversaries are now distributing malicious content across interconnected productivity tools including Outlook Groups, shared documents, calendar invitations, internal collaboration spaces, and cloud-hosted file repositories.

Attackers Are Turning Microsoft 365 Collaboration Into a Malware Delivery Platform

The result is a far more persistent and psychologically convincing attack chain where malicious activity blends directly into normal business workflows.

The Evolution Beyond Traditional Phishing

Classic phishing attacks have historically depended on urgency-driven email lures. Attackers impersonate vendors, executives, HR departments, financial institutions, or cloud service providers while embedding malicious links or weaponized attachments designed to trigger credential theft or malware execution.

Modern attackers increasingly understand one critical limitation of this approach.

Email security systems have improved dramatically.

Secure Email Gateways, sandboxing engines, attachment analysis systems, and behavioral detection platforms now routinely inspect suspicious attachments, detonate executables, analyze embedded URLs, and identify spoofed infrastructure before messages ever reach end users.

As a result, attackers have started moving malicious delivery mechanisms outside the email itself.

Instead of treating email as the final delivery vehicle, they now use it merely as the first touchpoint in a broader attack sequence.

Microsoft 365 Groups Becoming an Attack Surface

According to Fortra researchers, attackers are increasingly abusing Microsoft 365 Groups functionality to initiate phishing campaigns.

The attack typically begins when a victim receives what appears to be a legitimate invitation to join a Microsoft 365 Group controlled by the attacker. The group itself is carefully crafted to resemble normal organizational activity.

Group names often reference familiar administrative functions such as payroll processing, contract renewals, supplier documentation, employee onboarding, compliance reviews, procurement updates, or mandatory corporate training.

From the user’s perspective, nothing initially looks malicious.

After the user joins the group, the attacker gradually introduces malicious content through multiple Microsoft collaboration channels rather than sending a single suspicious email.

The campaign may involve:

  • Shared documents requiring review
  • Internal group messages requesting approval
  • Calendar invitations for mandatory meetings
  • Links to cloud-hosted files
  • Requests to access shared internal resources
  • Fake workflow notifications designed to mimic internal operations

The malicious intent becomes distributed across multiple trusted enterprise services.

CalPhishing: Weaponizing Calendar Infrastructure

One particularly effective technique growing rapidly in enterprise attacks is what researchers now call Calendar Phishing, or CalPhishing.

This method abuses Outlook calendar infrastructure to place phishing lures directly inside a victim’s work calendar through malicious meeting invitations or manipulated .ics calendar files.

Unlike traditional phishing emails that disappear once ignored, calendar events persist.

The malicious invitation remains visible on the user’s calendar for days or weeks while automated reminders repeatedly push the victim back toward the malicious content.

A user who ignored an initial email notification may later encounter:

  • Meeting invitations containing credential harvesting links
  • Calendar descriptions referencing shared files
  • Embedded QR codes leading to phishing portals
  • Fake internal approval workflows
  • Links requesting Microsoft authentication revalidation

Repeated exposure dramatically increases click probability.

Instead of a single phishing opportunity, attackers create an ongoing interaction loop.

Shared Files Becoming the Primary Malware Carrier

Perhaps the most dangerous evolution in these campaigns is the growing use of shared files as the actual malware delivery mechanism.

Traditional email security systems heavily inspect direct attachments, but attackers increasingly host malicious content inside trusted collaboration environments where files appear to originate from legitimate internal workflows.

The attack chain frequently moves through several stages.

An initial group invitation appears legitimate. A follow-up notification requests document review. The document resides inside what appears to be a shared internal workspace. The user downloads the file believing it to be part of an approved corporate process.

Only at this stage does malicious execution begin.

The shared file may contain:

  • Weaponized PDF documents embedding credential harvesting links, JavaScript triggers, fake payment requests, or browser redirection mechanisms.
  • Microsoft Office documents containing malicious macros, external template injection, embedded OLE objects, DDE exploitation, or hidden PowerShell execution triggers.
  • OneNote notebooks increasingly used to hide malicious HTA launchers, VBScript payloads, or embedded executable droppers.
  • Archive files including ZIP, RAR, or ISO containers designed to bypass mail gateway scanning while carrying malware loaders.
  • Shortcut files (.LNK) disguised as normal documents but executing hidden PowerShell or command-line payloads.

The user no longer perceives these files as suspicious attachments because they were retrieved through trusted collaboration workflows rather than direct email delivery.

Malware Families Commonly Delivered Through Collaboration-Based Phishing

Threat actors increasingly combine these collaboration workflows with malware families traditionally associated with credential theft and persistent access operations.

Recent incident response investigations have identified multiple malware families delivered through cloud-hosted shared documents and collaboration platforms.

Remcos RAT remains a frequent payload due to its lightweight remote access capabilities, clipboard monitoring, credential theft functions, and persistent command-and-control communications.

AsyncRAT campaigns frequently use shared cloud documents that trigger script-based PowerShell download chains.

Agent Tesla continues appearing in invoice-themed document attacks focused on browser credential harvesting and SMTP credential theft.

Lumma Stealer has increasingly appeared inside fake cloud collaboration notifications where malicious documents trigger browser session theft and cryptocurrency wallet extraction.

DarkGate operators frequently use cloud-hosted file-sharing platforms to stage secondary malware payload delivery after initial credential compromise.

In each case, the malware itself often remains secondary.

The primary objective is typically credential theft, session token hijacking, persistent cloud access, and privilege escalation inside corporate SaaS environments.

Why Distributed Phishing Campaigns Are Harder to Investigate

Security teams face a growing challenge because malicious activity is no longer isolated within email systems.

Traditional incident investigations often focus on:

  • Original phishing email
  • Sender infrastructure
  • Malicious attachment analysis
  • Embedded URL reputation checks

Modern collaboration-based phishing campaigns spread activity across multiple enterprise systems simultaneously.

An investigation may now require correlation between:

  • Exchange Online logs
  • Outlook Group membership changes
  • Calendar event creation history
  • SharePoint file access logs
  • OneDrive download telemetry
  • Azure AD authentication events
  • OAuth token creation activity
  • Endpoint execution logs after file download

This fragmentation creates visibility gaps that attackers deliberately exploit.

The Growing Shift Toward Malware-Free Intrusions

Another concerning trend is that many modern collaboration-based phishing attacks do not immediately deploy malware at all.

Instead, attackers focus on credential theft and session hijacking.

A fake shared document may redirect the user to a cloned Microsoft login portal. Stolen credentials then allow the attacker to generate OAuth tokens that bypass repeated authentication prompts.

From there, adversaries can silently access email accounts, cloud storage, internal documents, Teams conversations, financial records, and customer information without deploying traditional malware binaries.

Security products focused solely on malware detection may never trigger an alert.

Microsoft 365 potential outcome

Why Shared Files Must Be Treated Like Email Attachments

The largest misconception organizations continue making is assuming that files shared internally through collaboration platforms are inherently safer than files delivered directly through email.

Attackers understand this trust model.

A malicious file stored in SharePoint, distributed through Outlook Groups, referenced through calendar invitations, and downloaded from an apparently legitimate collaboration workspace often bypasses the psychological suspicion users naturally apply to external email attachments.

From a security perspective, shared cloud-hosted files should receive identical inspection treatment as inbound email attachments.

Every file entering enterprise collaboration workflows should be treated as an untrusted object until fully analyzed.

The modern phishing campaign is no longer an email attack.

It is increasingly a multi-surface delivery architecture where email, cloud collaboration systems, shared files, and trusted business workflows merge into a single coordinated attack chain.

Organizations that continue focusing only on inbox security risk missing where phishing campaigns are quietly evolving next.

References

  1. Fortra Research – Phishing Through Collaboration Fortra Blog Research Article
  2. Microsoft Security Intelligence – Business Email and Collaboration Threats Microsoft Security Blog
  3. Microsoft 365 Security Best Practices Microsoft 365 Security Documentation
  4. CISA Guidance on Phishing Resistant Authentication and Cloud Security CISA Cybersecurity Guidance 
  5. Proofpoint Threat Research on Collaboration App Abuse Proofpoint Threat Research