Large-Scale Azure-Hosted Tech Support Scam Campaign Targets Japan (13.38M Emails, 240K+ Relay IPs, 33K+ Disposable Azure Blob Storage Sites)
Large-Scale Azure-Hosted Tech Support Scam Campaign Targets (TL-2026-2595) is a high-severity phishing campaign, first published 2026-09-21. It has no confirmed attribution, affects Microsoft Azure Blob Storage (static website hosting), maps to 13 MITRE ATT&CK techniques (T1027, T1036.005, T1204.001), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-2595
- Threat ID
- TL-2026-2595
- Severity
- HIGH
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-09-21
- Last reviewed
- 2026-09-21
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, financial services impersonated, ecommerce, government tax authority impersonated, cross-sector enterprise workplace-themed phase
- Target regions
- japan, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Large-Scale Azure-Hosted Tech Support Scam Campaign Targets
Malware and tooling: AnyDesk, TeamViewer, AnyDesk, LogMeIn, RustDesk, ScreenConnect, TeamViewer, UltraViewer
Between mid-December 2025 and May 2026, a sustained tech support scam campaign sent 13.38 million emails (94% to .jp addresses) via 240,000+ globally distributed sending/relaying IP addresses, driving victims to 33,000+ disposable fake security-alert pages hosted on Microsoft Azure Blob Storage static website hosting. Victims who call the displayed North American (+1) support numbers are talked into installing legitimate remote-access software (AnyDesk, TeamViewer, RustDesk, ScreenConnect, UltraViewer, LogMeIn), leading to credential theft and fraudulent banking transactions.
How Large-Scale Azure-Hosted Tech Support Scam Campaign Targets works
Trend Micro tracked a 165-day tech support scam operation that sent 13.38 million emails at an average of ~81,000/day, peaking at 4.45 million emails (~160,000/day) in February 2026 and settling to a sustained ~30,000/day by May 2026. Ninety-four percent of targeted addresses used Japan's .jp top-level domain, and delivery timing was tuned to Japan Standard Time business hours (09:00-21:00 JST).
Delivery infrastructure comprised more than 240,000 sending/relaying IP addresses distributed globally (Brazil contributed the largest email volume; China the most unique source IPs). A subset of this infrastructure fingerprinted as legitimate, internet-exposed network devices rather than dedicated attacker infrastructure: 3,231 relaying IPs ran MikroTik services, of which 2,657 exposed MikroTik's TCP/2000 (bandwidth-test) service to the internet, alongside 284 exposing OpenSSH, 184 exposing nginx, and 144 exposing Apache. This fingerprint is consistent with hijacked/unmanaged IoT and small-office router equipment being recruited as spam relays, a pattern independently documented in unrelated 2025 MikroTik-botnet malspam reporting.
Landing infrastructure used Microsoft Azure Blob Storage's static website hosting feature to serve more than 33,000 disposable fake security-alert pages; roughly 90% were used for only a single day before rotation, and page content was encrypted to evade content-based scanners. Abuse of Azure Blob Storage's trusted, Microsoft-issued-TLS static hosting for phishing/scam landing pages mirrors broader 2025-2026 industry reporting on cloud-native phishing infrastructure abuse.
The campaign's lures evolved in two phases. From mid-December 2025 through March 2026, lures were generic: fake security warnings, adult-content pretexts, and impersonation of e-commerce platforms, financial institutions, and tax agencies. From April 2026 onward, the operators shifted to workplace-themed social engineering aimed at individuals inside organizations, with subject lines such as "[Urgent] Internal network security audit: Request to verify suspicious device activity and logs," "[Confidential] Advance release of the H2 FY2026 performance evaluations and promotion candidate list," "[Important / All employees] Confirmation of H2 FY2026 salary revisions and evaluation feedback," "[Employee benefits] Notice: Digital Amazon gift cards for all employees," "[Important notice] Changes to commuting expense reimbursement rules," and "[Urgent] Request for confirmation regarding flat-rate tax cut and refund procedures." More than 90% of sender addresses were spoofed to match the recipient's own address, a technique intended to defeat casual sender-legitimacy checks and increase open rates.
The monetization chain is classic callback phishing / Telephone-Oriented Attack Delivery (TOAD): the email or landing page displays a support phone number; the victim calls it; a live operator instructs the victim to install a remote-access tool (AnyDesk, TeamViewer, RustDesk, ScreenConnect, UltraViewer, or LogMeIn); the operator then uses that access to harvest credentials, navigate the victim into their online banking portal, and extract fraudulent fees or transfers. Trend Micro identified 11-12 distinct callback phone numbers reused across 4,721 of the fake alert sites (February-May 2026 data, current as of June 12, 2026); the numbers use Japan's "010" international access prefix followed by North American (+1) numbers, indicating a North America-based call operation servicing Japanese victims.
Japan's National Police Agency's 2025 fraud statistics show "support-pretext" billing fraud (the category corresponding to tech support scams) at 1,048 reported cases (down 31.2% year-over-year) but 1.49 billion yen in losses (up 48.1% year-over-year) -- meaning far fewer victims are being defrauded, but for roughly double the average amount per case, consistent with the campaign's April 2026 pivot toward higher-value enterprise/workplace targets.
No threat-actor attribution is offered in available reporting. This campaign is a distinct operation from, but part of the same broader tech-support-scam ecosystem as, Barracuda's May 2026 "CypherLoc" browser-locking scareware kit report; the two should not be conflated as the same infrastructure or toolset absent further evidence.
MITRE ATT&CK techniques used in TL-2026-2595
Defense Evasion
T1027 Obfuscated Files or Information; T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
Initial Access
T1566.002 Spearphishing Link; T1566.004 Spearphishing Voice
Resource Development
T1583.006 Web Services; T1584.005 Botnet
Reconnaissance
T1589.002 Email Addresses; T1598.003 Spearphishing Link
Impact
Affected products and versions in Large-Scale Azure-Hosted Tech Support Scam Campaign Targets
- Microsoft — Azure Blob Storage (static website hosting)
Vulnerable versions: N/A -- abused as trusted, Microsoft-TLS-backed hosting infrastructure for disposable phishing/scam landing pages, not a software vulnerability
Fixed in: N/A - MikroTik — RouterOS-based devices with internet-exposed management/bandwidth-test services
Vulnerable versions: Devices with internet-accessible TCP/2000 (bandwidth-test), SSH, or HTTP admin services, consistent with unmanaged/hijacked units recruited as spam relays
Fixed in: N/A -- restrict management-plane exposure to the internet - Multiple — Individual and organizational email users at .jp domains (Japan)
Vulnerable versions: N/A -- social-engineering campaign targeting end users, not a software product
Fixed in: N/A
Remediation for Large-Scale Azure-Hosted Tech Support Scam Campaign Targets
Immediate actions
- Enforce SPF, DKIM, and DMARC (with a reject/quarantine policy) on all inbound mail flows to catch senders spoofed to match the recipient's own address or internal domains
- Block or restrict installation of consumer/SMB remote-access tools (AnyDesk, TeamViewer, RustDesk, ScreenConnect, UltraViewer, LogMeIn) on non-IT-managed endpoints via application allow-listing
- Alert on outbound international calls dialed via Japan's '010' access prefix to North American (+1) numbers occurring shortly after a user clicks a security-alert email link
- Brief HR, payroll, and IT helpdesk teams on the workplace-themed subject-line lures (performance review, salary revision, security audit, gift card, expense-policy, tax-refund pretexts) currently in use
Workarounds
- Require employees to verify unsolicited 'urgent' HR/IT/security emails through a known internal channel (ticketing system, verified intranet contact) before calling any phone number contained in the email or a linked page
- Restrict or monitor outbound international voice calling for employees where feasible, particularly to the North American numbers identified as IOCs for this campaign
Longer-term hardening
- Deploy multi-layer email security with URL and page-content inspection capable of following links to Azure Blob Storage static-website hosts (*.blob.core.windows.net / *.z##.web.core.windows.net) rather than trusting the domain by reputation alone
- Inventory and remediate internet-exposed MikroTik/IoT and small-office router management interfaces (e.g., TCP/2000 bandwidth-test service, exposed SSH/HTTP admin panels) that could be recruited as spam-relay infrastructure
- Run recurring, scenario-based security-awareness training emphasizing urgency-based social engineering and callback-phishing (TOAD) tactics, not just malicious-link recognition
- Establish a verified callback-number registry for internal IT/HR/security communications so employees can distinguish legitimate outreach from spoofed workplace-themed lures
Timeline of Large-Scale Azure-Hosted Tech Support Scam Campaign Targets
- Campaign begins sending fake security-alert emails to Japanese (.jp) addresses, linking to disposable landing pages hosted on Microsoft Azure Blob Storage static website hosting.
- Campaign reaches its peak monthly volume of 4.45 million emails (~160,000/day) in February 2026.
- Japan Times reports 2025 fraud figures showing specialized/support-pretext fraud losses at record highs nationally, providing corroborating context for the campaign's financial-fraud outcomes.
- Lures pivot from generic security/adult-content/financial-institution/tax-agency impersonation to workplace-themed subject lines targeting employees inside organizations (performance reviews, salary revisions, internal security audits, gift-card notices, expense-policy changes, tax-refund pretexts).
- Campaign volume declines from its February peak to a sustained ~30,000 emails/day while remaining active.
- Barracuda Networks separately publishes a report on 'CypherLoc,' a browser-locking scareware kit that also drives victims to fraudulent tech-support calls, illustrating the broader tech-support-scam ecosystem active during the same period (distinct infrastructure/toolset from this campaign).
- Trend Micro's tracked set of reused scam callback phone numbers (11-12 numbers across 4,721 fake alert sites, February-May 2026) is current as of this date.
- Trend Micro publishes 'Tech Support Scams Targeting Japan,' detailing the campaign's infrastructure, lure evolution, and scale.
Sources cited for Large-Scale Azure-Hosted Tech Support Scam Campaign Targets
- 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
- Inside the attack chain: Threat activity targeting Azure Blob Storage
- 13,000 MikroTik Routers Hijacked by Botnet for Malspam and Cyberattacks
- Threat Spotlight: CypherLoc, an advanced browser-locking scareware targeting millions
- Fraud soars to record high in Japan as scam tactics grow more sophisticated
- Fake Police Scams Double in Japan as Financial Losses from Fraud Soar
More in phishing
- Phishing Campaign Impersonates ChatGPT Subscription Billing Alerts to Steal OpenAI Credentials via Google API Open-Redirect and nxcli.io Infrastructure
- Global Fake Parcel Delivery Phishing/Smishing Campaign Steals Card and Bank Details
- Fake myGov 'Secure Message' Phishing Scam Targets Australians with Multi-Step Identity Harvesting Flow
- Revolut Phishing SMS Campaign Follows Social-Engineering Data Breach Exposing 680 Customers' KYC Data
- Fake ChatGPT Billing Email Phishing Campaign Abuses Google API Redirect to Steal OpenAI Credentials via nxcli.io
Detection coverage for TL-2026-2595
As of 2026-09-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2595 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.