The Ghost in the Machine: How a Multi-Stage Phishing Campaign Evades Security to Steal Microsoft 365 Credentials
ID: 6e677fdf-bb1f-5839-8cdb-c68537282ae5
STIX ID: report--6e677fdf-bb1f-5839-8cdb-c68537282ae5
Feed Name: KnowBe4 Blog
KnowBe4 Threat Labs describes an active, highly sophisticated multi-stage phishing campaign (observed since November 3, 2025) that uses nested PDF attachments and legitimate CDN services to obfuscate a credential-harvesting webpage which implements nine advanced evasion techniques (DevTools detection, anti-debugging, viewport monitoring, hidden honeypot fields, behavioral mouse tracking, console overrides, text obfuscation, network monitoring, etc.) and a real-time man-in-the-middle relay that leverages Microsoft infrastructure to validate credentials and relay MFA challenges, enabling immediate takeover of Microsoft 365 accounts; recommended mitigations include layered cloud email security, blocking identified IOCs, auditing MFA authentications, and user awareness training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
