VYPR
advisoryPublished Sep 2, 2026· 1 source

Hackers Exploit Microsoft 365, RMM Tools in Widespread Session Hijacking Campaigns

Cyberattacks in August targeted US and EU firms using sophisticated phishing lures to hijack Microsoft 365 sessions and abuse legitimate remote management tools.

A significant wave of cyberattacks in August targeted organizations across the United States and Europe, leveraging a combination of Microsoft 365 session hijacking and the abuse of legitimate remote management tools (RMMs). Security researchers observed campaigns that effectively blended malicious activity with normal administrative operations, making detection a considerable challenge.

The primary vector involved phishing lures disguised as legitimate business documents, such as fake tax notices, invoices, and shipping confirmations. These lures were designed to trick recipients into downloading and installing signed RMM applications, including widely used tools like ScreenConnect, ConnectWise, and LogMeIn Rescue. Because these RMMs are essential for IT support and administration, their presence on a network often goes unquestioned, allowing attackers to operate with a degree of stealth.

One notable phishing-as-a-service kit, identified as Mirage2FA, proved particularly effective, compromising over 4,000 U.S. victims. This kit employed adversary-in-the-middle (AiTM) techniques, using a reverse proxy architecture to intercept not only user credentials but also multi-factor authentication (MFA) codes and active session cookies. This allowed attackers to hijack active Microsoft 365 sessions, gaining access to sensitive corporate data, cloud files, and financial systems, even after users had completed MFA challenges.

Beyond RMM abuse, the attacks also featured the deployment of the SnakeBiteAgent RAT (Remote Access Trojan). This malware was delivered via business-themed ZIP archives and, once executed, granted attackers capabilities such as credential theft, keylogging, and webcam access. Furthermore, it facilitated the silent installation of other remote access tools like AnyDesk, deepening the compromise.

Another phishing kit, dubbed 3DBlast, impersonated Microsoft 365 and Google login pages. It utilized advanced techniques like browser-in-the-browser (BitB) attacks and OAuth device-code phishing, combined with real-time session relay. This sophisticated approach allowed the kit to rotate its infrastructure rapidly, evading static detection methods and enabling persistent credential and session harvesting.

In a separate, but related, incident, researchers uncovered the activities of a group tracked as Famous Chollima, suspected to be linked to Lazarus. This group used forged identities to pass remote employment screening at a fictitious DeFi startup. Once onboarded, they gained legitimate access to source code and internal systems, highlighting a novel approach to supply chain compromise through insider threat vectors.

Security experts emphasize that compromised Microsoft 365 sessions can remain valid even after a user's password has been reset. Therefore, organizations must implement robust measures beyond simple password changes, such as revoking active session tokens and diligently monitoring for unauthorized RMM installations. Strengthening identity verification for remote employees, deploying phishing-resistant MFA solutions, and leveraging behavioral threat intelligence to track evolving attacker infrastructure are critical steps in mitigating these pervasive threats.

The interconnected nature of these attacks underscores the need for a multi-layered security approach. Organizations should consider adopting advanced threat intelligence, such as sandbox analysis, to investigate suspicious files and URLs proactively. This allows for the identification and neutralization of threats before they can escalate into significant business disruptions.

Synthesized by Vypr AI