- An old Microsoft Stream -Domain was recently hijacked
- Many SharePoint -Webotes with embedded videos showed the malicious content
- Microsoft quickly addressed the problem so users had to update now
A retired Microsoft domain was hijacked and used in a spam campaign, experts have warned.
Microsoft used to have an Enterprise Video Sharing Platform called Stream, where organizations could safely upload, manage and share video content. In April 2024, it was retired and replaced by Microsoft Stream at SharePoint.
The most important difference is that the videos were no longer stored separately in the power platform, but rather on OneDrive and SharePoint to make them more accessible through Microsoft 365 tools such as team, Yammer or PowerPoint.
“Appropriate action”
Today, almost a year after migration, news came out of the older domain – microsoftstream.com – was hijacked and used to show a fake Amazon place advertising a Thai casino.
The biggest problem with this attack is that all SharePoint sites with old embedded videos showed spam in their premises.
Bleeping computer Found a number of users complaining about the acquisition at Reddit:
“This afternoon, a user reported a suspicious site on our intranet using Microsoftstream.com. After some analysis, it turns out that the domain is currently redirecting to a outlined site signed by ‘Ibiza99’,” a user said. “Here’s an interesting to all of you. I just got a call that our SharePoint site showed spam instead of embedded videos. Interesting, I thought. I wonder how it might happen,” added another.
No further information about the attack was shared, but Microsoft was soon notified of the change, and it moved quickly to remedy the problem and said, “We are aware of these reports and have taken appropriate steps to further prevent access to affected domains”.
Apparently, the old domain could have been in more creepy campaigns that, for example, distributed malware through fake software updates. However, good news is that attackers chose the least harmful thing – a spam campaign.