{"success":true,"data":{"id":"azure-monitor-callback-lure","label":"Azure Monitor callback lure — azure-noreply@microsoft.com + fraud/unauthorized charge + phone CTA","description":"Email is sent from Microsoft's real azure-noreply@microsoft.com address but the body contains callback-phishing scam content (fraud resolution hotline, unauthorized charge language, fake Windows Defender renewal) with an attacker-controlled phone number. Attackers compromise or create an Azure subscription, configure malicious Alert Rules with scam content in the alert description, add victim email to the Action Group, then trigger the alert — causing Microsoft's own infrastructure to deliver the phish. Passes SPF/DKIM/DMARC. Active campaign documented by SpiderLabs in April 2026.","tier":"danger","category":"other","isThin":false}}