Kaspersky logs 4.7m attacks mimicking Zoom, Outlook and OneDrive

Kaspersky detected nearly 4.8 million attempted attacks disguised as workplace tools in the 12 months to June 2026, with Zoom the most abused brand.

An empty, brightly lit control room features a large curved video wall displaying a glowing blue-green data visualization, with multiple rows of workstations equipped with computer monitors and chairs.

Kaspersky has published threat data showing 4,781,846 attempted attacks in the 12 months to June 2026 that used content impersonating widely used enterprise collaboration platforms. The research, released ahead of what the firm calls the "business season" return from summer, highlights how attackers time campaigns to coincide with predictable spikes in workplace digital activity.

Zoom was the most frequently abused brand, appearing in 2,658,283 of the detected attempts. Outlook was second with 1,546,122 detections, followed by OneDrive with 197,030, Microsoft Excel with 151,948 and Microsoft Teams with 111,402. Kaspersky also monitored keywords associated with Gmail, Dropbox, Figma, Google Drive, Basecamp and Slack, though the release does not break out figures for those services individually.

Attack techniques

The dominant threat category by volume was Downloaders, accounting for 2,733,204 cases. These programs establish a foothold and fetch additional malicious payloads, making them a common first-stage tool for ransomware and espionage operations. Trojans were the second-largest category at 989,377 detections, followed by Exploits targeting software or operating-system vulnerabilities at 341,165 cases.

Beyond volume counts, Kaspersky highlighted two social-engineering techniques of particular note. The first involves Microsoft's Device Authorization Grant flow, a legitimate mechanism that allows authentication on input-limited devices. Attackers initiate the OAuth flow for an application they control, then trick victims into entering a displayed code on a genuine Microsoft login page. The result is an authorisation token, not stolen credentials, which means the victim's password is never directly exposed and MFA completion by the user still grants the attacker access to email, OneDrive and Teams content. The second technique used Google's AppSheet platform to distribute fake interview invitations purportedly from Google's recruitment team. Because the messages originate from a genuine AppSheet address, standard domain-inspection advice provides little protection.

Evgeny Kuskov, Lead Security Researcher at Kaspersky, noted that the danger "is not necessarily an obviously suspicious message, but one that looks ordinary enough to be opened without a second thought."

Market context

Kaspersky's data sits within a broader pattern documented by multiple threat-intelligence vendors: business-email compromise and credential-phishing volumes tend to track workforce activity cycles, with spikes around return-from-holiday periods and major enterprise software roll-outs. The device-code phishing technique Kaspersky describes has been flagged by Microsoft's own threat-intelligence team and by several incident-response firms over the past 18 months as an emerging vector targeting organisations that have deployed MFA, since it bypasses password interception entirely.

The abuse of legitimate platforms such as Google AppSheet to distribute phishing payloads reflects a wider attacker strategy of routing malicious content through trusted sending infrastructure to defeat reputation-based email filtering. Security vendors including Proofpoint, Mimecast and others have documented similar abuse of Salesforce, DocuSign and SharePoint in comparable campaigns.

For enterprise security teams, the practical implication is that perimeter email filtering alone is insufficient. Endpoint detection capable of identifying Downloader behaviour post-execution, combined with conditional-access policies that restrict device-code authentication flows to managed devices, are the near-term controls most relevant to the threats Kaspersky describes. Kaspersky recommends its own Kaspersky Next platform alongside standard hygiene measures including MFA, verified download sources and regular security-awareness training.

The findings are based on Kaspersky's own telemetry and have not been independently validated by a third party. The report does not disclose the geographic distribution of the attempted attacks or the industry verticals most frequently targeted.