< Back to all clusters
[TECHNOLOGY] · United States, Austria, Germany · 6 sources

started · updated

Microsoft 365 users targeted by sophisticated MFA-bypass phishing attacks

Cybercriminals are increasingly utilizing sophisticated phishing techniques to bypass multi-factor authentication (MFA) and hijack Microsoft 365 sessions. Security researchers from Arctic Wolf and CloudSEK have identified major operations, such as PREY-0058 and BigBear 2.0, which use adversary-in-the-middle (AiTM) frameworks like Evilginx2. These attacks route traffic through residential proxies to mimic legitimate user locations, allowing attackers to intercept authenticated session cookies after a victim has successfully completed MFA.

CloudSEK reported that the BigBear 2.0 operation targeted 461 organizations across more than 40 countries, harvesting thousands of credential records and session cookies. Similarly, Arctic Wolf noted that attackers use vishing (voice phishing) to trick executives into visiting fraudulent authentication pages that impersonate their own companies.

Regional reports highlight the growing impact of these methods. In Austria, a study by the Vienna Chamber of Commerce and KPMG found that cybercriminals are becoming more professional through the use of artificial intelligence. In Germany, the IHK for Oberfranken Bayreuth warned of a surge in phishing attacks targeting Microsoft 365 environments in the Upper Franconia region, noting that even established MFA may not provide reliable protection against these advanced methods.

Entities

Arctic Wolf · CloudSEK · IHK für Oberfranken Bayreuth · KnowBe4 · Microsoft · Vanuatu · Vienna Chamber of Commerce · whitelisthackers GmbH