Using classic Outlook for Windows in business environments
As someone who tests software for a living, I can say with certainty that this is an attack specifically aimed at Outlook and no other service. The reason for it is because of how Microsoft set up Outlook to only block domains on their Junk Folder. This means a botnet can send crazy amounts of phishing emails using phony domains without having to change the prefix on an email address and there's no way for users to block any of it. The fact that it goes directly into the Junk Folder is by design from this particular hacking group. What they're hoping for is someone will click on one of the two links they have in their emails accidentally when they go to try and delete them.
It's clear to me that Microsoft doesn't seem to see this as a threat to their users and believe it to be an inconvenience that they can let go without consequence. Given the nature and danger of this particular attack, this is being grossly misjudged. These emails are dangerous and need to be blocked such that they never get to the Junk Folder. It does make me wonder if there's a way to get US federal regulators involved to force MS to do the right thing and protect its users from harm.
Either way, this whole thing has been extremely disappointing to me. I've used Outlook and Microsoft 365 (PAID) for years and this is the first time I feel like I don't matter as a customer. It's not fun having to spend chunks of my day scanning through all those "preview" emails in my Junk Folder to make sure nothing legitimate has made it into there. It used to be about 4 emails per hour. It appears to have increased over the last week or so. Probably because this hacking group managed to increase the size of its botnet.