Cambrient
×
skillbit
Co-published research
Threat Intelligence  ·  Security Training

The link looks safe.
That is the problem.

Modern phishing no longer fakes a website. It borrows the trust of a real one. Here are four live campaigns that abuse Meta, Apple, Microsoft, and Zoom against you, shown in real captures, and what it takes to stop them.

By Cambrient & SkillBit|Threat & Training brief|9 min read

For years, phishing training gave people a simple rule: check the link. That advice still matters. But it is starting to feel incomplete.

Some of the most interesting phishing attacks today are not built around obviously fake domains, broken English, or strange attachments. They are built around trusted platforms that employees already use: Meta, Microsoft, Zoom, Apple, Google, Dropbox, DocuSign, and dozens of other SaaS tools.

The attacker's goal is not always to make a fake website look real. Increasingly, the goal is to use a real platform in a malicious way. A user might see a real Meta notification. A real Zoom sender. A Microsoft Customer Voice page. An Apple TestFlight install flow. Nothing about the first step feels obviously wrong, because in many cases the infrastructure really is legitimate.

The danger starts when the user assumes that a trusted platform makes every next click safe. The four campaigns below are all real, all documented by security researchers in 2025, and all built on exactly that assumption.

01

The Meta Business Manager partner request

One recent campaign abuses Meta Business Suite partner requests. The attacker does not need to spoof Meta from the outside. They create a real partner request through Meta's own workflow, so Meta sends the notification from its real infrastructure. The sender looks right. The template looks right. SPF, DKIM, and DMARC all pass.

The malicious piece is buried inside the request. Because the auto-generated invitation button cannot be edited, the attacker names the fake business after a "partner program" and drops an off-domain link at the top of the message. For a marketer or agency employee, partner requests are a normal part of the day. That is what makes it effective. The email is not fake. The business process has been weaponized.

business.facebook.com › partner invitationReal capture
A genuine Meta partner-program invitation delivered by Meta's own infrastructure, with the attacker-controlled link placed above the un-editable “View invitation” button.
Fig.A genuine Meta partner-program invitation delivered by Meta's own infrastructure, with the attacker-controlled link placed above the un-editable “View invitation” button. Source: Sublime Security.
agency-partner-register[.]com › Meta Agency Partner ProgramReal capture
The off-domain landing page, built from a real Meta “Privacy Centre” template and dressed up as an agency partner program before it asks for credentials.
Fig.The off-domain landing page, built from a real Meta “Privacy Centre” template and dressed up as an agency partner program before it asks for credentials. Source: Sublime Security.

The right question is not only, "Did this really come from Meta?" It is, "Does the destination and the request actually make sense for Meta?"

02

The fake Meta Ads Manager app through TestFlight

Another campaign targets advertisers with a fake Meta Ads Manager app. Victims are pushed to install it through Apple TestFlight, and some variants reportedly reached the App Store before removal. That is a powerful trust signal. Most people do not think of Apple's app distribution as part of a phishing chain.

By routing the victim through TestFlight, the scam stops feeling like "click this random link" and starts feeling like "install this business tool." Once installed, the counterfeit app harvests credentials, cookies, tokens, and ad-account access.

mail › “Meta Inc has invited you to test Ads Manager Suite”Real capture
The lure email invites the advertiser to “test” an Ads Manager app, framing an install as a routine beta rather than a download from a stranger.
Fig.The lure email invites the advertiser to “test” an Ads Manager app, framing an install as a routine beta rather than a download from a stranger. Source: Sublime Security.
apps.apple.com › TestFlight › Ads Meta ManagerReal capture
The real Apple TestFlight install screen for the counterfeit “Ads Meta Manager,” complete with a developer name and expiry date. Trusted distribution, malicious intent.
Fig.The real Apple TestFlight install screen for the counterfeit “Ads Meta Manager,” complete with a developer name and expiry date. Trusted distribution, malicious intent. Source: Sublime Security.

The lesson is not "Apple is unsafe" or "TestFlight is bad." It is that trusted distribution does not automatically mean trusted intent. The user still has to ask: Why am I being asked to install this? Was I expecting it? Would I find the same app by going directly through the official provider?

03

Microsoft Customer Voice phishing

Microsoft Dynamics 365 Customer Voice is a legitimate survey product, which is exactly why attackers reach for it. Campaigns themed around invoices, voicemails, and shared documents send links to real customervoice.microsoft.com pages. The first page belongs to Microsoft. Inside it sits one more link, sometimes behind a CAPTCHA, that leads to a fake Microsoft login.

customervoice.microsoft.com › ResponsePage.aspxReal capture
A genuine Microsoft Customer Voice page hosting an “eFax” lure. The domain is real Microsoft; the content inside it is attacker-controlled.
Fig.A genuine Microsoft Customer Voice page hosting an “eFax” lure. The domain is real Microsoft; the content inside it is attacker-controlled. Source: Cofense.
•••.workers.dev › Enter passwordReal capture
Two clicks later: the spoofed Microsoft password prompt on an unrelated domain, where the credentials are actually captured.
Fig.Two clicks later: the spoofed Microsoft password prompt on an unrelated domain, where the credentials are actually captured. Source: Cofense.

This is why "check the domain" is no longer enough by itself. A Microsoft page can still contain attacker content. A trusted page can still point somewhere else. Users need to learn to pause after the first click, not just before it.

04

Zoom abuse and trusted notification flows

Zoom-themed attacks follow the same pattern. Some abuse Zoom Docs or Zoom Events notifications; others wrap themselves in document, invitation, or payment alerts. The dangerous part may not be a meeting link at all. It may be a document link, an external redirect, a fake support number, or a credential page reached after the first, innocent-looking interaction.

docs.zoom.us › shared document › Review & ApproveReal capture
A real docs.zoom.us page carrying a DocuSign-styled panel. Employees are used to clicking Zoom links, so the trusted hop rarely gets a second look.
Fig.A real docs.zoom.us page carrying a DocuSign-styled panel. Employees are used to clicking Zoom links, so the trusted hop rarely gets a second look. Source: Keep Aware.
•••.r2.dev › Sign In to Join MeetingReal capture
The credential-phishing destination: a spoofed Zoom Workplace sign-in with the victim's email pre-filled, hosted well away from Zoom.
Fig.The credential-phishing destination: a spoofed Zoom Workplace sign-in with the victim's email pre-filled, hosted well away from Zoom. Source: Cofense.

The user still has to evaluate the action being requested. Is this actually a meeting? Is it asking me to download software I did not request? Is it sending me away from Zoom, or asking me to sign in to Microsoft after I clicked a Zoom document? Those are context questions. They are harder to teach than "look for typos," but they are far more useful against modern phishing.

The new rule

Trust the context, not just the platform.

A safe platform does not make every action safe.
A real email does not make every link inside it safe.
A legitimate workflow can still be abused.
A familiar brand can still be part of an attacker's path.

The most important question is not, "Do I recognize this platform?" It is, "Does this request make sense?"

A training problem, not just a tools problem

You cannot teach this with a once-a-year slide that says "hover over links."

These attacks require pattern recognition. People need practice walking the whole sequence: sender, platform, link, destination, request, second click, credential prompt, download, and business context. That is a perfect fit for hands-on, scenario-based training, and it is exactly what SkillBit builds.

Imagine a short lab where a learner gets a real-looking Meta partner request and has to find where the trust breaks. A Zoom document notification whose sender is clean but whose next page asks for something strange. A Customer Voice page where the suspicious part is not the Microsoft domain, but the link embedded inside the survey. That kind of practice builds judgment, not just awareness.

SkillBit Labs
Cyber skills, bit by bit
01
Hands-on, not slideware
Bite-sized labs that mirror real cyber workflows, built on a 20-minute rule.
02
Scenario-based judgment
Learners make the real decisions attackers count on, in a safe environment.
03
Measured capability
Skills assessment that shows who can actually spot a weaponized workflow.

The old lesson was: be careful before you click. The new lesson is: be careful even after the first click looks safe. Modern phishing is more contextual, more platform-native, and more dependent on abusing legitimate workflows. So the training has to become more contextual too.

Two halves of one defense

Investigate the link. Train the judgment.

Cambrient

Autonomous AI agents that investigate every message the way an analyst would, follow every link and attachment to its end, and act in milliseconds. We open the link before your users do.

Book a Cambrient demo →
SkillBit

Hands-on, scenario-based cyber training that builds the judgment these attacks are designed to beat. Give your team the reps to spot a weaponized workflow before they click.

Explore SkillBit Labs →
Cambrient
×
skillbit

Screenshots are real captures reproduced from published threat research for educational purposes, credited to Sublime Security, Cofense, and Keep Aware. Campaign analysis also draws on Check Point Harmony research. Cambrient and SkillBit are not affiliated with Meta, Apple, Microsoft, or Zoom; brand names are used only to identify the platforms abused in these attacks.