logo

New VENOM phishing attacks steal senior executives' Microsoft logins

ID: e18c213a-ba98-5c73-857d-e38ea0b72120

STIX ID: report--e18c213a-ba98-5c73-857d-e38ea0b72120

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-04-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors operating a closed-access phishing-as-a-service platform called VENOM have been targeting C-suite Microsoft accounts since at least last November. Using highly personalized SharePoint-themed emails, Unicode QR codes that route victims to researcher-filtered landing pages, and either adversary-in-the-middle (AiTM) credential relaying or device-code approval flows, VENOM captures credentials, MFA codes, and session tokens; researchers warn these methods can bypass standard MFA and recommend FIDO2, disabling device-code flows when unnecessary, and stricter conditional access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.