Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 7 sources · 12 days · First seen · Last updated
Microsoft 365 phishing and MFA bypass threats
Overview
Cybersecurity researchers have identified evolving phishing threats specifically targeting Microsoft 365 environments. Initially, the discovery of the ‘NovaCookies’ phishing-as-a-service toolkit revealed a subscription-based model designed to bypass multi-factor authentication (MFA) via adversary-in-the-middle (AiTM) techniques. This toolkit has targeted hundreds of organizations globally, including in the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates, sometimes using counterfeit Docusign notifications to lure victims.
Subsequent reports indicate a continued surge in these types of attacks. In Germany, experts warned of a specific method dubbed ‘Kali365’ that uses convincing messages appearing to be official Microsoft requests to bypass MFA. Additionally, attackers are shifting their infrastructure to avoid detection; as traditional domains are blocked, there has been a significant increase in the use of new top-level domains, such as a 159.6 percent rise in malicious sites using the .vu domain from Vanuatu.
Recent intelligence from Arctic Wolf and CloudSEK highlights major operations like PREY-0058 and BigBear 2.0, which utilize AiTM frameworks such as Evilginx2. These operations route traffic through residential proxies to mimic legitimate user locations, enabling attackers to intercept authenticated session cookies after MFA is completed. CloudSEK reported that BigBear 2.0 targeted 461 organizations across more than 40 countries, harvesting thousands of credentials and session cookies.
Attackers are also employing vishing to trick executives into visiting fraudulent authentication pages. In Austria, researchers noted that cybercriminals are becoming more professional through the use of artificial intelligence, while regional warnings in Germany emphasize that even established MFA may not provide reliable protection against these advanced methods.
Entities
CloudSEK · NovaCookies · whitelisthackers GmbH · KnowBe4 · Island
Timeline
-
4 days ago
[TECHNOLOGY] 6 sourcesMicrosoft 365 users targeted by sophisticated MFA-bypass phishing attacksCybercriminals are using advanced phishing and AiTM techniques to bypass MFA and hijack Microsoft 365 sessions, targeting organizations globally through sophisticated session cookie theft.
-
16 days ago
[TECHNOLOGY] 2 sourcesNovaCookies phishing toolkit targets Microsoft 365 sessionsNovaCookies, a $320-per-month phishing-as-a-service toolkit, is stealing Microsoft 365 sessions by bypassing MFA through adversary-in-the-middle attacks, targeting hundreds of global organizations.
Sources
bayreuther-tagblatt.de · businesstechweekly.com · computerworld.com · cybernoz.com · it-boltwise.de · it-daily.net · meinegemeinde.vol.at
This summary has been updated 1 time: see revision history