Secure Bulletin Navigating the cyber sea with knowledge
Home > Articolo > Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools
Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools
Read Time:3 Minute, 26 Second

Trusted business tools become attack infrastructure

A cluster of attacks observed across the United States and Europe shows how criminals are combining identity theft with software that organizations already trust. Campaigns documented in an August threat review used Microsoft 365 lures, signed remote-monitoring and management applications, and ordinary-looking business files to gain access while blending into administrative traffic.

Victims received fake tax notices, invoices, and shipping documents that encouraged them to install tools such as ScreenConnect, ConnectWise, or LogMeIn Rescue. Those products are legitimate and widely deployed by help desks, so their network traffic and signed binaries may avoid controls designed to stop obviously malicious payloads. Once installed under false pretenses, however, they give an intruder durable interactive access and a platform for credential collection or further deployment.

MFA does not stop a stolen session

The Mirage2FA phishing-as-a-service kit reportedly compromised more than 4,000 people in the United States and appeared in activity covering 46 countries. Its adversary-in-the-middle design relayed a genuine sign-in while capturing usernames, passwords, multifactor codes, and the resulting session cookie. With that cookie, an attacker can reuse an already authenticated Microsoft 365 session instead of repeatedly challenging the victim's MFA.

This technique exposes email, cloud documents, contact lists, and financial conversations. It can also support internal phishing from a familiar account. A password change alone may not end the intrusion because an issued token can remain valid until it expires or is explicitly revoked. Incident response therefore needs to include forced sign-out, token revocation, review of registered authentication methods, and investigation of OAuth grants and mailbox rules.

A wider toolkit surrounds the identity attacks

Researchers also identified SnakeBiteAgent, a .NET remote-access trojan distributed in business-themed ZIP files. Its reported functions include keylogging, credential theft, webcam access, and quiet installation of AnyDesk. Another kit, 3DBlast, imitated Microsoft 365 and Google authentication using browser-in-the-browser windows, OAuth device-code phishing, and real-time session relay, while rotating infrastructure to frustrate simple blocklists.

A separate part of the research described suspected Lazarus-linked operators tracked as Famous Chollima. The actors allegedly used fabricated identities to pass remote-employment screening and obtain legitimate access inside a deceptive decentralized-finance startup. Although distinct from the mass phishing activity, the episode reinforces the same theme: attackers increasingly exploit trusted workflows and valid access rather than relying only on detectable malware.

What security teams should change

Organizations should prioritize phishing-resistant authentication such as hardware-backed passkeys or FIDO2 security keys for sensitive roles. Conditional-access policies can restrict unusual devices, locations, and token use, but alerts must feed an operational response that revokes sessions quickly. Administrators should inventory approved RMM products, block or alert on unauthorized alternatives, and monitor new installations, unattended-access configuration, and unexpected support sessions.

Email controls should scrutinize archive attachments and business-document lures without assuming that a signed executable is safe. Security teams can also hunt for impossible travel, unfamiliar user agents, newly granted OAuth consent, anomalous downloads, and inbox-rule changes. Remote hiring requires strong identity verification and tightly limited initial privileges. The campaigns demonstrate that defenders must correlate identity, endpoint, and cloud activity: each individual signal may look legitimate, while the combined sequence reveals an account takeover in progress.

Practical security takeaway

This event also underlines the importance of layered controls and rehearsed incident response. Organizations should document ownership for identity, endpoint, cloud, and developer tooling; retain the telemetry needed to connect activity across those systems; and test containment procedures before an emergency. Security teams should translate vendor guidance into measurable checks rather than treating an update or configuration change as the end of the investigation. Where exposure is possible, defenders should establish a time window, identify affected assets and accounts, preserve relevant evidence, and verify that remediation actually removed persistence. Users and administrators should rely on official update channels, avoid unverified fixes, and report suspicious behavior promptly. These steps cannot eliminate every attack path, but they reduce both the likelihood that an initial foothold succeeds and the damage an intruder can cause after gaining access.

Share: Twitter  |  Facebook  |  LinkedIn
Join the discussion

This is a blog in the Fediverse: you can find this article everywhere with @blog@securebulletin.com and every comment/answer will appear here.

If you want to comment on Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools, use the discussion on Forum.

>> forum community

Comments

Leave a Reply