logo

Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse

ID: 450de62f-8f3c-5257-8b54-3c19ade266b3

STIX ID: report--450de62f-8f3c-5257-8b54-3c19ade266b3

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-09-02

Date Updated: 2026-09-16

Author: Balaji N

...
...

A coordinated August campaign abused widely trusted tools and phishing-as-a-service kits (Mirage2FA, 3DBlast) to perform AiTM session hijacking of Microsoft 365 accounts, install RATs like SnakeBiteAgent, and deploy signed remote-management software to maintain stealthy persistent access; researchers also tie suspected Lazarus-linked operatives ('Famous Chollima') using fake remote-hire identities to gain internal access. Organizations are advised to revoke active tokens, adopt phishing-resistant MFA, strengthen remote-hire identity checks, and use behavioral threat intelligence and sandboxing to detect rotating attacker infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.