CyberheistNews Vol 15 #49 Ghost in the Machine: How a Multi-Stage Phishing Attack Evades M365 Security
ID: 0aefbf95-7f4f-5b43-8a21-16d190fc8583
STIX ID: report--0aefbf95-7f4f-5b43-8a21-16d190fc8583
Feed Name: KnowBe4 Blog
CyberheistNews Vol.15#49 summarizes several active and emerging threats: a multi-stage phishing campaign (since Nov 3, 2025) engineered to bypass SEGs and MFA to harvest Microsoft 365 credentials; a broad campaign using fake holiday party invites to install various RMM tools; a fileless Matrix Push C2 platform abusing browser push notifications for social-engineering and C2; and malicious AI toolkits (WormGPT 4, KawaiiGPT) that lower the skill barrier for phishing and ransomware. The bulletin highlights advanced evasive techniques, global targeting, and active exploitation observed by multiple security vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
