started · updated
Microsoft authentication systems targeted in multi‑stage cyber attacks
Threat actors are increasingly abusing legitimate remote‑access tools (RATs) such as ConnectWise, N‑Able, SimpleHelp, Datto RMM and GoTo to run multi‑stage campaigns that start with phishing emails and malicious websites, install a RAT, then download additional payloads to maintain persistence and sell access to compromised networks.
A separate campaign hijacks hotel and conference‑center Wi‑Fi gateways by gaining administrative access and altering DNS settings. The modified DNS redirects guests to fake Microsoft 365 login pages, stealing credentials. Compromised gateways have been identified in several U.S. cities, India and Saudi Arabia and the attacks have hit firms in financial services, professional services, legal, healthcare, energy and retail sectors.
A third wave of phishing uses Microsoft’s own authentication flow. Over 200 phishing emails sent to roughly 120 organizations worldwide between late June and early July 2026 impersonated Microsoft Teams task notifications. Recipients were taken to a genuine Microsoft sign‑in page and then prompted to grant permissions to an attacker‑controlled application, allowing the attackers to capture OAuth tokens and potentially access corporate resources.
Entities
ConnectWise · Datto RMM · GoTo · Microsoft · N‑Able
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] The hotel Wi‑Fi campaign has targeted organizations in financial services, professional services, legal, healthcare, energy and retail sectors. itnerd.blog
- [○ 1 SOURCE] Over 200 phishing emails were sent to about 120 organizations worldwide between June 25 and early July 2026. www.itvoice.in
- [○ 1 SOURCE] Compromised Wi‑Fi gateways have been found in multiple U.S. cities, India and Saudi Arabia. itnerd.blog
- [○ 1 SOURCE] Multi‑stage RAT attacks increased in early 2026, often beginning with phishing emails and malicious websites delivering the RAT.
- [○ 1 SOURCE] Hackers hijack hotel and conference‑center Wi‑Fi gateway DNS settings to redirect users to counterfeit Microsoft 365 login pages and steal credentials. itnerd.blog
- [○ 1 SOURCE] Phishing campaign impersonated Microsoft Teams task notifications and used a legitimate Microsoft sign‑in page to obtain OAuth tokens. www.itvoice.in
- [○ 1 SOURCE] Threat actors are using legitimate remote‑access tools (RATs) such as ConnectWise, N‑Able, SimpleHelp, Datto RMM and GoTo in multi‑stage attack chains.
- [○ 1 SOURCE] Victims were prompted to grant permissions to an attacker‑controlled application, allowing attackers to capture access tokens. www.itvoice.in