A wave of cyberattacks across the US and Europe in August exploited the trust businesses place in everyday tools, turning Microsoft 365 logins, remote-management software, and routine business documents into entry points for attackers.
Security researchers tracked campaigns that combined account takeover, persistent remote access, and credential theft, often disguised as legitimate activity.
Microsoft 365 Session Hijacking
Research from ANY.RUN, highlighted in their August cyberattack analysis, uncovered a phishing operation spanning 46 countries, with nearly half of observed activity tied to the United States.
Attackers used fake tax notices, invoices, and shipping documents to trick victims into installing signed remote management tools such as ScreenConnect, ConnectWise, and LogMeIn Rescue.
Because these applications are widely used for legitimate IT support, the malicious activity often blended in with normal administrative traffic, making detection difficult without behavioral analysis.
A large-scale phishing-as-a-service kit called Mirage2FA compromised more than 4,000 US victims by intercepting credentials, MFA codes, and session cookies through adversary-in-the-middle techniques.
This allowed attackers to hijack active Microsoft 365 sessions even after users completed multi-factor authentication, exposing corporate email, cloud files, and finance workflows across the technology, manufacturing, and education sectors.
Researchers also identified SnakeBiteAgent, a .NET remote access trojan delivered inside business-themed ZIP archives that granted attackers credential theft, keylogging, and webcam access, plus silent installation of remote-access tools like AnyDesk.
Separately, a phishing kit dubbed 3DBlast impersonated Microsoft 365 and Google login pages using browser-in-the-browser, OAuth device-code phishing, and real-time session relay techniques, rotating infrastructure to evade static detection.
| Threat Actor / Tool | Delivery & Technical Mechanism | Operational Impact & Targeting |
| RMM Abuse Campaign | Phishing lures (fake tax, invoice, and shipping notices) | Installs signed ScreenConnect and ConnectWise tools to bypass perimeter filters |
| Mirage2FA PaaS Kit | Reverse proxy Adversary-in-the-Middle (AiTM) architecture | Intercepts session cookies and MFA tokens to compromise 4,000+ M365 accounts |
| SnakeBiteAgent RAT | Business-themed ZIP archives (.NET executable payload) | Executes keylogging, webcam snooping, and silent AnyDesk installation |
| 3DBlast Phishing Kit | Browser-in-the-browser & OAuth device-code phishing | Impersonates Microsoft 365 and Google portals via real-time session relay |
| Famous Chollima | Forged identities passing remote employment screening | Penetrates DeFi startups to obtain persistent source code and internal access |
A joint investigation involving ANY.RUN exposed suspected Lazarus-linked operatives, tracked as Famous Chollima, who used forged identities to pass remote hiring checks at a fake DeFi startup, gaining legitimate access to source code and internal systems once onboarded.
Security researchers noted that stolen Microsoft 365 sessions can remain valid even after password resets, meaning organizations must revoke active tokens and monitor for unusual RMM installations rather than relying on single indicators of compromise.
Enterprises are advised to strengthen identity verification for remote hires, deploy phishing-resistant MFA, and use behavioral threat intelligence to trace rotating attacker infrastructure before incidents escalate into broader business exposure.
Organizations looking to reduce detection gaps can strengthen enterprise defenses by adopting sandbox-driven threat intelligence or by exploring interactive analysis features to investigate suspicious files and URLs before they compromise business-critical systems.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse appeared first on Cyber Security News.
