Attackers sent victims to a legitimate Microsoft login page and then asked them to approve app permissions.