Back to Blog

Case Study: How Nimblr honeypots detected a multi-stage phishing attack

Case Study: How Nimblr honeypots detected a multi-stage phishing attack.

A multi-stage phishing attack hides its malicious payload behind one or more legitimate-looking steps, so the first link looks harmless and only a later one steals your credentials. This case study walks through a real example our honeypots caught: a phishing email sent from a compromised Microsoft Exchange account, a genuine OneDrive document as the first layer, and a fake Microsoft login page two clicks deep.It is a clear illustration of how phishing works.

Background: behavioral threats over technical exploits

Unlike attacks that target infrastructure or zero-day vulnerabilities, this campaign focused on end users. The attacker set out to steal Microsoft 365 credentials through a chain of deceptive steps. Nimblr's honeypot, a decoy email address embedded in a realistic fake corporate website, captured the phishing email in real time.

Step by step: anatomy of the attack

Step 1: Delivery via legitimate infrastructure. The phishing email came from a legitimate but compromised Microsoft Exchange account belonging to the event organizer's CEO. Because it came from a trusted source, most spam filters and security checks failed to flag it.

Step 2: Deceptive content and timing. The email referenced a "project proposal" and linked to a document hosted on Microsoft OneDrive. Timing it just before a major sports event raised click-through rates by exploiting urgency and relevance.

Step 3: Use of a trusted platform as a first layer. The initial OneDrive link led to a genuine Microsoft-hosted page, which reinforced the email's legitimacy. That page contained a document with a second embedded link.

Step 4: Payload delivery via indirect link. Only the secondary link revealed malicious content: a fake Microsoft login page built to harvest credentials. It mimicked Microsoft branding closely, with only a non-Microsoft URL as a clue, something most users would miss.

Threat analysis and containment

After detection, Nimblr's team ran a structured analysis:

Header inspection revealed the legitimate routing and sending domains.
Code review uncovered obfuscated scripts capturing credentials.
Sandbox testing safely extracted indicators of compromise (IOCs).
Attribution and mitigation identified the hosting provider, registrar, and script origins.

Despite immediate outreach, the malicious OneDrive document stayed online for six days, which highlights the coordination gaps between organizations and their IT vendors.

Why did traditional security miss it?

This attack shows a growing trend: abusing legitimate platforms like OneDrive, Exchange, and SharePoint to deliver multi-stage payloads that bypass perimeter defenses. The initial payload looked benign, and the malicious behavior only emerged deeper in the chain. It is the same pattern behind the OneDrive phishing attack our team uncovered separately.

Outcome and operational impact

Key takeaways for CISOs and IT managers

Multi-stage phishing is rising, with legitimate services weaponized against automated filters.

Credential compromise can come from a trusted contact, so verify unexpected content regardless of who sent it.

Proactive intelligence makes the difference, since honeypots enable early detection and rapid response.

Frequently asked questions

What is a multi-stage phishing attack?

An attack that splits itself across several steps so each one looks harmless on its own. The first link usually leads to a legitimate platform, and the credential-stealing page is hidden one or two clicks deeper, which helps it slip past automated filters.

How did this attack get past spam filters?

It was sent from a real, compromised Microsoft Exchange account and used a genuine Microsoft OneDrive link as the first layer, so the message came from a trusted source and pointed to a trusted domain.

Why do attackers abuse services like OneDrive and Exchange?

Because security tools tend to trust well-known domains. Hosting the first stage on Microsoft infrastructure makes the message look legitimate and buys the attacker time.

How can organizations detect multi-stage phishing?

Layer human and technical defenses: threat intelligence and honeypots for early detection, and regular phishing simulations so employees learn to check the final URL before entering credentials.

Author

Nimblr Security Awareness

Nimblr Security Awareness

The Nimblr team is made up of people who are passionate about cyber security, developing training for real people, and tracking behavioral change.