Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cyberattacks Exploit Microsoft 365 in US and EU

Cyberattacks Exploit Microsoft 365 in US and EU

Posted on September 2, 2026 By CWS

A series of cyberattacks in August targeted businesses across the United States and Europe, exploiting common tools like Microsoft 365. These attacks used remote management software and business documents as entry points, leveraging the trust companies place in these everyday tools.

Understanding the Attack Methods

Security experts observed operations that combined techniques such as account takeover, persistent remote access, and credential theft, often masquerading as legitimate actions. These campaigns were tracked by researchers who identified them as significant threats to business operations.

Microsoft 365 Session Hijacking

Research by ANY.RUN detailed a phishing operation affecting 46 countries, with the United States experiencing nearly half of the activity. Attackers deployed fraudulent tax notices, invoices, and shipping documents to deceive victims into installing signed remote management tools like ScreenConnect and ConnectWise, which are typically used for legitimate IT support.

The malicious use of these tools made detection challenging without advanced behavioral analysis. A phishing-as-a-service kit known as Mirage2FA exploited adversary-in-the-middle techniques to intercept credentials and session cookies, compromising over 4,000 Microsoft 365 accounts. This breach allowed attackers to access corporate emails and cloud files even post multi-factor authentication, affecting sectors such as technology, manufacturing, and education.

Additional Threats Identified

Researchers found the SnakeBiteAgent, a .NET remote access trojan delivered through business-themed ZIP archives, enabling attackers to steal credentials, log keystrokes, and access webcams. The trojan also facilitated the silent installation of remote-access tools like AnyDesk.

Another phishing kit, 3DBlast, impersonated Microsoft 365 and Google login pages using sophisticated techniques like browser-in-the-browser and OAuth device-code phishing. This kit rotated infrastructure to avoid detection, further complicating defense efforts.

Recommendations for Enterprises

In a joint investigation, ANY.RUN exposed operatives linked to the Lazarus group, dubbed Famous Chollima, who infiltrated a fake DeFi startup by posing as remote IT workers. This allowed them to access source code and internal systems.

Experts emphasize that compromised Microsoft 365 sessions can remain active even after password resets. Therefore, organizations should revoke active tokens and monitor for unusual remote management tool installations. Strengthening identity verification for remote hires and deploying phishing-resistant MFA are advised. Additionally, utilizing behavioral threat intelligence to trace attacker infrastructure can prevent broader business exposure.

Companies aiming to close detection gaps should consider adopting sandbox-driven threat intelligence and interactive analysis tools to investigate suspicious files and URLs before they affect critical systems.

Cyber Security News Tags:ANY.RUN, credential theft, cyber threats, Cybersecurity, EU, FAMOUS CHOLLIMA, MFA, Microsoft 365, Phishing, phishing kits, remote access, RMM abuse, session hijacking, SnakeBiteAgent, US

Post navigation

Previous Post: WhatsApp Flaw Exposes Android Photos via Video Call
Next Post: Dropbox Breach Exposes 5,000 Accounts via Lenovo ID Flaw

Related Posts

Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Critical Convoy Vulnerability Let Attackers Execute Remote Code on Affected Servers Cyber Security News
SCALR AI: A Free AI Platform for Security Teams SCALR AI: A Free AI Platform for Security Teams Cyber Security News
Claude Cowork Enhances AI Session Management on Mobile Claude Cowork Enhances AI Session Management on Mobile Cyber Security News
Vulnerability in TP-Link Kasa Devices Exposes Security Risks Vulnerability in TP-Link Kasa Devices Exposes Security Risks Cyber Security News
Critical Vulnerability in TP-Link Routers Exposed Critical Vulnerability in TP-Link Routers Exposed Cyber Security News
Remcos RAT Masquerade as VeraCrypt Installers Steals Users Login Credentials Remcos RAT Masquerade as VeraCrypt Installers Steals Users Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Cleo Harmony Flaw Puts Networks at Risk
  • Dropbox Breach Exposes 5,000 Accounts via Lenovo ID Flaw
  • Cyberattacks Exploit Microsoft 365 in US and EU
  • WhatsApp Flaw Exposes Android Photos via Video Call
  • Authorities Dismantle Sality Botnet, Halting Malware Spread

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Cleo Harmony Flaw Puts Networks at Risk
  • Dropbox Breach Exposes 5,000 Accounts via Lenovo ID Flaw
  • Cyberattacks Exploit Microsoft 365 in US and EU
  • WhatsApp Flaw Exposes Android Photos via Video Call
  • Authorities Dismantle Sality Botnet, Halting Malware Spread

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark