< Back to situation

[REVISION HISTORY]

Microsoft 365 phishing and MFA bypass threats

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-09-08 08:01 UTC → 2026-09-09 02:35 UTC · added removed

Cybersecurity researchers have identified evolving phishing threats specifically targeting Microsoft 365 environments. Initially, the discovery of the ‘NovaCookies’ phishing-as-a-service toolkit revealed a subscription-based model designed to bypass multi-factor authentication (MFA) via adversary-in-the-middle (AiTM) techniques. This toolkit has targeted hundreds of organizations globally, including in the United States, United Kingdom, Canada, Germany, Israel, and the United Arab Emirates, sometimes using counterfeit Docusign notifications to lure victims. Subsequent reports indicate a continued surge in these types of attacks. In Germany, experts warned of a specific method dubbed ‘Kali365’ that uses convincing messages appearing to be official Microsoft requests to bypass MFA. Additionally, attackers are shifting their infrastructure to avoid detection; as traditional domains are blocked, there has been a significant increase in the use of new top-level domains, such as a 159.6 percent rise in malicious sites using the .vu domain from Vanuatu. Recent intelligence from Arctic Wolf and CloudSEK highlights major operations like PREY-0058 and BigBear 2.0, which utilize AiTM frameworks such as Evilginx2. These operations route traffic through residential proxies to mimic legitimate user locations, enabling attackers to intercept authenticated session cookies after MFA is completed. CloudSEK reported that BigBear 2.0 targeted 461 organizations across more than 40 countries, harvesting thousands of credentials and session cookies. Attackers are also employing vishing to trick executives into visiting fraudulent authentication pages. In Austria, researchers noted that cybercriminals are becoming more professional through the use of artificial intelligence, while regional warnings in Germany emphasize that even established MFA may not provide reliable protection against these advanced methods.

Versions

  1. 2026-09-09 02:35 UTC Microsoft 365 phishing and MFA bypass threats
  2. 2026-09-08 08:01 UTC Microsoft 365 phishing and MFA bypass threats

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.