Abuse of "PerfectData Software" May Create a Perfect Storm | Darktrace Blog
Amidst the ever-changing threat landscape, new tactics, techniques, and procedures (TTPs) seem to emerge daily, creating extreme challenges for security teams. The broad range of attack methods utilized by attackers seems to present an insurmountable problem: how do you defend against a playbook that does not yet exist? Faced with the growing number of novel and uncommon attack methods, it is essential for organizations to adopt a security solution able to detect threats based on their anomalies, rather than relying on threat intelligence alone. In March 2023, Darktrace observed an emerging trend in the use of an application known as ‘PerfectData Software’ for probable malicious purposes in several Microsoft 365 account takeovers. Using its anomaly-based detection, Darktrace was able to identify the activity chain surrounding the use of this application, potentially uncovering a novel piece of threat actor tradecraft in the process. In recent years, Microsoft’s Software-as-a-Service (S
PerfectData Software Abuse and Account Takeover Risks Solutions Why Darktrace Partners Resources Get a demo Solutions Why Darktrace Partners Resources Get a demo Blog / Identity / June 5, 2023 PerfectData Software Abuse and Account Takeover Risks Darktrace investigates several attacks through PerfectData Software on Microsoft 365 accounts and shows how we were able to prevent full account takeovers. Written by Dariush Onsori Cyber Security Analyst Written by Sam Lister Specialist Security Researcher Inside the SOC Darktrace cyber analysts are world-class experts in threat intelligence, threat
Explore this link on the map →saved by
related reading
- Email Compromise To Mass Phishing Campaigndarktrace.com
- Malicious Azure Application PERFECTDATA SOFTWARE and Microsoft 365 Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- Common Oauth Apps Used in Business Email Compromise - Syne's Cyber Cornercybercorner.tech
- The Soze Syndicate - Business Email Compromise Campaign | Todyltodyl.com
- Exposing and shutting down an inbox heist in actionredcanary.com
- Cloud coverage: Detecting an email payroll diversion attackredcanary.com
- Shifting detection left for more effective threat detectionpushsecurity.com
- Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2softwareanalyst.substack.com
- Entra ID service principals in business email compromise schemes | Red Canaryredcanary.com
- Security incident disclosure — July 2026huggingface.co
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar | Dragosdragos.com