logo

Hunt Before They Hide -From Device Codes to Fake IT Support Detecting Active Microsoft 365 Identity…

ID: d030b9bd-2c4f-549c-8820-125fbc3a004b

STIX ID: report--d030b9bd-2c4f-549c-8820-125fbc3a004b

Feed Name: Detect FYI

Threat Score
85/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Rohitashokgowd

...
...

This report documents a set of active, high-impact Microsoft 365 account takeover techniques—device code phishing, AiTM proxying, silent MFA device registration, SMS passwordless abuse, and Teams helpdesk impersonation—used by both state-aligned APTs and criminal PhaaS operators. It identifies named groups and commoditized services (Storm-2372, VENOM, Kali365, EvilTokens, Tycoon2FA, SNOW variants), prescribes mitigations (deny device-code by default, require FIDO2, require admin approval for MFA registrations, restrict Teams external access), and provides 12 detailed detection/hunting KQL rules to identify and respond to compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.