Cybercriminals use workplace tools to disguise 4.7 million attacks

Kaspersky found malicious downloaders were the most common threat, with 2.73 million cases, followed by 989,377 trojan detections.

 


4.7 million cyberattack attempts used workplace tools as lures between July 2025 and June 2026.

Zoom accounted for 2,658,283 attempts, followed by Outlook with 1,546,122 detections; OneDrive recorded 197,030, Microsoft Excel 151,948 and Microsoft Teams 111,402.


4.7 million cyberattack attempts used workplace tools as lures between July 2025 and June 2026. Zoom accounted for 2,658,283 attempts, followed by Outlook with 1,546,122 detections; OneDrive recorded 197,030, Microsoft Excel 151,948 and Microsoft Teams 111,402.

The attacks sought to blend in with employees’ routine communications: fake meeting invitations, malicious files presented as work documents and phishing pages replicating the appearance of familiar email or cloud storage services.

Kaspersky’s analysis identified this activity over a 12-month period, from July 2025 to June 2026. The platforms used as lures are part of everyday workplace activities, which can make it harder for users to distinguish legitimate communications from fraud attempts.

Malicious files remain a common entry point

Among the threats detected, downloaders were the most frequent, with 2,733,204 cases. This type of program can download and install other files or programs on a victim’s device, creating opportunities for additional threats to be introduced.

Trojans ranked second, with 989,377 detections. These programs can disguise themselves as legitimate files or applications and be used to steal information, monitor user activity, enable remote access to a device or install additional malware.

The analysis also recorded 341,165 exploits, threats designed to take advantage of vulnerabilities in programs or operating systems and compromise devices.

Legitimate code can also be used to deceive

Among the campaigns analyzed was a phishing technique aimed at compromising corporate accounts through device codes. Instead of directly requesting a password on a fake page, attackers generate a valid code and trick users into entering it on an official Microsoft login page.

Users may complete the authentication process normally and even use multifactor authentication without realizing they are authorizing an application controlled by the attackers. This allows cybercriminals to obtain an authorization token without directly obtaining the password.

This access can allow them to view emails, files stored in OneDrive or Microsoft Teams conversations. The fact that part of the process takes place on an official Microsoft page can also make the deception harder to identify.

Fake job offers also serve as lures

Researchers also identified fake job interview invitations that appeared to come from Google’s recruiting team. The messages claimed that the recipient’s professional profile had attracted the company’s attention and invited them to schedule an initial conversation through a link.

In this case, the attackers used Google AppSheet, a legitimate Google platform, to distribute the emails. The messages came from an authentic service address, which could increase their credibility. The link in the supposed invitation led to a phishing site designed to collect personal information and credentials.

This type of deception can be particularly effective during periods of increased job activity and hiring. A communication from a legitimate service or an apparently personalized opportunity can reduce suspicion and lead users to follow a link before checking whether the position actually exists through the company’s official channels.

”One of the main advantages cybercriminals have today is that they no longer need to create messages that seem extraordinary to attract attention. They only need to imitate routine workplace actions, such as opening an invitation, viewing a shared file or validating access. When these interactions become automatic, people pay less attention to each request and are more likely to authorize access, download files or provide information without recognizing the deception. For organizations, an apparently routine action by a single employee can become an entry point for compromising corporate accounts, accessing sensitive information or spreading an attack to other systems,” said Lisandro Ubiedo, Senior Security Researcher at Kaspersky’s Global Research and Analysis Team (GReAT).

What to check before opening or authorizing

To reduce risks from messages impersonating workplace tools, Kaspersky recommends not relying solely on the appearance or name of a familiar platform. Before opening an invitation, shared document or account notification, users should check who sent the message and where the link leads.

The company also recommends paying attention to small changes in addresses and confirming unexpected requests through another channel.

Another recommendation is to carefully review any access request. A legitimate page does not guarantee that the request it presents is also legitimate.

If a login code appears that the user did not request, or an application asks for unexpected permissions to access email, files or a corporate account, users should stop the process and verify what they are authorizing, even when multifactor authentication is being used.

Kaspersky also recommends using different passwords for each service, enabling multifactor authentication and keeping the operating system, browser and workplace applications up to date. Updates fix vulnerabilities that cybercriminals can exploit to compromise devices.

The analysis included platforms such as Gmail, Dropbox, Figma, Google Drive, Basecamp and Slack, in addition to Zoom, Outlook, OneDrive, Microsoft Excel and Microsoft Teams.


Share:
Hosting Web
Most Read