# Microsoft 365 phishing and MFA bypass threats

> Live situation record from CLSTR: https://clstr.news/situations/microsoft-365-phishing-and-mfa-bypass-threats
> Updated: 2026-09-08T00:00:00.000Z. Sources: 7. Developments: 2.

Cybersecurity researchers have identified evolving phishing threats specifically targeting Microsoft 365 environments. Initially, the discovery of the ‘NovaCookies’ phishing-as-a-service toolkit revealed a subscription-based model designed to bypass multi-factor authentication (MFA) via adversary-in-the-middle (AiTM) techniques. This toolkit has targeted hundreds of organizations globally, including in the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates, sometimes using counterfeit Docusign notifications to lure victims.

Subsequent reports indicate a continued surge in these types of attacks. In Germany, experts warned of a specific method dubbed ‘Kali365’ that uses convincing messages appearing to be official Microsoft requests to bypass MFA. Additionally, attackers are shifting their infrastructure to avoid detection; as traditional domains are blocked, there has been a significant increase in the use of new top-level domains, such as a 159.6 percent rise in malicious sites using the .vu domain from Vanuatu.

Recent intelligence from Arctic Wolf and CloudSEK highlights major operations like PREY-0058 and BigBear 2.0, which utilize AiTM frameworks such as Evilginx2. These operations route traffic through residential proxies to mimic legitimate user locations, enabling attackers to intercept authenticated session cookies after MFA is completed. CloudSEK reported that BigBear 2.0 targeted 461 organizations across more than 40 countries, harvesting thousands of credentials and session cookies.

Attackers are also employing vishing to trick executives into visiting fraudulent authentication pages. In Austria, researchers noted that cybercriminals are becoming more professional through the use of artificial intelligence, while regional warnings in Germany emphasize that even established MFA may not provide reliable protection against these advanced methods.

## Timeline

### 2026-09-08: Microsoft 365 users targeted by sophisticated MFA-bypass phishing attacks

Cybercriminals are using advanced phishing and AiTM techniques to bypass MFA and hijack Microsoft 365 sessions, targeting organizations globally through sophisticated session cookie theft.

6 sources. https://clstr.news/cluster/cybersecurity-threats-evolve-with-microsoft-365-phishing-and-new-domain-usage

### 2026-08-27: NovaCookies phishing toolkit targets Microsoft 365 sessions

NovaCookies, a $320-per-month phishing-as-a-service toolkit, is stealing Microsoft 365 sessions by bypassing MFA through adversary-in-the-middle attacks, targeting hundreds of global organizations.

2 sources. https://clstr.news/cluster/novacookies-phishing-toolkit-targets-microsoft-365-sessions

---
Cite as: Microsoft 365 phishing and MFA bypass threats. CLSTR, https://clstr.news/situations/microsoft-365-phishing-and-mfa-bypass-threats
