A series of cyberattacks in August targeted businesses across the United States and Europe, exploiting common tools like Microsoft 365. These attacks used remote management software and business documents as entry points, leveraging the trust companies place in these everyday tools.
Understanding the Attack Methods
Security experts observed operations that combined techniques such as account takeover, persistent remote access, and credential theft, often masquerading as legitimate actions. These campaigns were tracked by researchers who identified them as significant threats to business operations.
Microsoft 365 Session Hijacking
Research by ANY.RUN detailed a phishing operation affecting 46 countries, with the United States experiencing nearly half of the activity. Attackers deployed fraudulent tax notices, invoices, and shipping documents to deceive victims into installing signed remote management tools like ScreenConnect and ConnectWise, which are typically used for legitimate IT support.
The malicious use of these tools made detection challenging without advanced behavioral analysis. A phishing-as-a-service kit known as Mirage2FA exploited adversary-in-the-middle techniques to intercept credentials and session cookies, compromising over 4,000 Microsoft 365 accounts. This breach allowed attackers to access corporate emails and cloud files even post multi-factor authentication, affecting sectors such as technology, manufacturing, and education.
Additional Threats Identified
Researchers found the SnakeBiteAgent, a .NET remote access trojan delivered through business-themed ZIP archives, enabling attackers to steal credentials, log keystrokes, and access webcams. The trojan also facilitated the silent installation of remote-access tools like AnyDesk.
Another phishing kit, 3DBlast, impersonated Microsoft 365 and Google login pages using sophisticated techniques like browser-in-the-browser and OAuth device-code phishing. This kit rotated infrastructure to avoid detection, further complicating defense efforts.
Recommendations for Enterprises
In a joint investigation, ANY.RUN exposed operatives linked to the Lazarus group, dubbed Famous Chollima, who infiltrated a fake DeFi startup by posing as remote IT workers. This allowed them to access source code and internal systems.
Experts emphasize that compromised Microsoft 365 sessions can remain active even after password resets. Therefore, organizations should revoke active tokens and monitor for unusual remote management tool installations. Strengthening identity verification for remote hires and deploying phishing-resistant MFA are advised. Additionally, utilizing behavioral threat intelligence to trace attacker infrastructure can prevent broader business exposure.
Companies aiming to close detection gaps should consider adopting sandbox-driven threat intelligence and interactive analysis tools to investigate suspicious files and URLs before they affect critical systems.
