
by AKANI CHAUKE
JOHANNESBURG, (CAJ News) – CYBERCRIMINALS are increasingly disguising malicious files, links and account-stealing campaigns as everyday workplace tools, with Kaspersky detecting nearly 4.8 million attempted attacks exploiting the names of popular business platforms over the past year.
The cybersecurity company said its analysis, covering July 2025 to June 2026, recorded 4,781,846 attempted attacks involving content associated with services including Zoom, Outlook, OneDrive, Microsoft Excel and Teams.
Zoom was the most abused brand, accounting for 2,658,283 attempted attacks, followed by Outlook with 1,546,122. OneDrive recorded 197,030 detections, Microsoft Excel 151,948 and Teams 111,402.
The findings highlight how criminals exploit routine workplace behaviour, particularly when employees return from seasonal breaks and face a surge in meetings, emails, shared documents and recruitment activity.
Kaspersky said downloaders represented the largest threat category, with 2,733,204 detections. These programmes can install additional malicious software.
Trojans followed with 989,377 detections, potentially enabling data theft, surveillance, remote access or further malware installation. Exploits accounted for another 341,165 cases.
Some campaigns demonstrated why conventional phishing awareness is no longer enough.
Kaspersky researchers identified attacks abusing Microsoft’s legitimate Device Authorisation Grant process.
Victims were tricked into entering a code generated for an attacker-controlled application on a genuine Microsoft login page.
By completing the process, including potentially multi-factor authentication, victims could unknowingly grant attackers access to emails, OneDrive files and Teams messages.
Another campaign impersonated Google’s recruitment team, using legitimate Google AppSheet infrastructure to distribute fake interview invitations. Recipients were redirected to phishing sites designed to harvest personal information and credentials.
“Cybercriminals understand this context and may imitate exactly the tools people expect to encounter during the working day,” said Evgeny Kuskov, Kaspersky’s lead security researcher. He warned that the most dangerous message may be one ordinary enough to escape scrutiny.
The lesson for businesses is clear: trust in familiar brands cannot become a substitute for verification.
Kaspersky advises workers to scrutinise senders and links, obtain software from authorised sources, avoid unexpected requests to disable security settings, use unique passwords and enable multi-factor authentication.
Companies should also verify unusual payment, document-sharing and access requests through separate channels and provide regular training using realistic phishing scenarios.
As hybrid working and cloud collaboration become entrenched, attackers are increasingly targeting the trust surrounding digital tools.
For businesses, cybersecurity is therefore no longer simply an IT concern; it is a frontline defence for data, money and operational continuity.
– CAJ News