Microsoft warned that extortion groups including ShinyHunters are running passkey and single-sign-on-themed phishing to break into Microsoft 365 accounts. Attackers impersonate the IT help desk by call, text, or Teams message, urging employees to urgently update a passkey or MFA setting, then send them to fake login pages. The passkey angle is only a lure: the real goal is to capture credentials and session tokens through an adversary-in-the-middle site or a device-code approval that bypasses MFA. Once in, they register their own authentication method for persistence, so a password reset alone will not evict them, then quietly exfiltrate under a thousand files an hour to blend in, spreading through connected single-sign-on services.
Researchers at CloudSEK gained access to the control panel of BigBear, a phishing-as-a-service platform that defeated multi-factor authentication at 258 organizations and stole thousands of Microsoft 365 credentials. It uses an adversary-in-the-middle proxy based on Evilginx to sit between victims and Microsoft's real login, capturing passwords, multi-factor codes, and the session cookie, then replaying the cookie to hijack the already-authenticated session. The panel logged over 5,000 stolen records across 40-plus countries and is rented to multiple affiliates who receive stolen data through Telegram bots. Notably, it runs JavaScript that disables the browser's passkey support, forcing victims off phishing-resistant login onto weaker methods it can intercept.
A commercial phishing-as-a-service toolkit called Mirage2FA has hit around 4,500 organizations by abusing legitimate Microsoft 365 login flows to steal passwords and session cookies and bypass two-factor authentication. Because it captures the session cookie after a real login completes, the attacker inherits an authenticated Microsoft 365 session and any single-sign-on connected services, defeating multi-factor authentication. Researchers at ANY.RUN linked the campaign to more than 9,000 potential compromise events and found that nearly half of targeted addresses may have been affected, with most victims in the United States across technology, manufacturing, and education. Hijacking one session can expand into connected apps and internal workflows.
A phishing operator left a Python web server exposed with directory listing on, letting researchers at Lexfo lift the entire toolkit and pivot to two more operators running three Microsoft 365 phishing campaigns. Each used a custom fork of the open-source Evilginx proxy to steal live session cookies and tokens, defeating multi-factor authentication by relaying the real login. The largest campaign ran over a year, logging 218 captured accounts, mostly corporate mailboxes, and a token file left in a public repository held 97 live Microsoft tokens. The report stresses two different MFA-bypass methods appeared, one proxying the real login and one abusing the device-code flow, which require different defenses to stop.
A new phishing-as-a-service platform called Forg365 is built to steal Microsoft 365 accounts, combining adversary-in-the-middle and device-code phishing with AI-generated lures created directly in its control panel. Researchers at ZeroBEC found the panel lets operators build campaigns, configure malicious OAuth apps, generate and refine phishing emails with AI, and monitor compromised mailboxes for keywords, all in one place. It also ships a browser extension that silently refreshes session cookies through an OAuth flow, giving attackers ongoing access without re-authenticating. The operators deliver lures posing as business documents, using legitimate email-sending infrastructure to slip past filters. The researchers note AI is lowering the cost of both writing phishing content and building phishing platforms.
Microsoft disclosed Monday that a phishing campaign between April 14 and 16 hit 35,000+ users across 13,000+ organizations in 26 countries (92% in the US). Lures impersonated internal HR with subjects like 'Internal case log issued under conduct policy.' Each email had a PDF attachment with a 'Review Case Materials' link that walked victims through Cloudflare CAPTCHAs and a final adversary-in-the-middle (AiTM) Microsoft sign-in page. AiTM proxies the real Microsoft login and captures session tokens after MFA - so traditional MFA is bypassed. Healthcare (19%), financial services (18%), and professional services (11%) were the most-targeted sectors.
CrowdStrike disclosed two cybercrime groups - Cordial Spider and Snarky Spider - running fast SaaS extortion attacks that stay almost entirely inside legitimate SaaS environments. The pattern: call employees pretending to be IT support, walk them through an 'MFA reset' that's actually a credential-harvesting site that mimics their company's branding, capture the password and MFA code, then immediately log into SSO and pivot through Microsoft 365, Salesforce, and other SaaS apps. The attackers register their own device for MFA and exfiltrate data within hours. Both groups overlap with the broader ShinyHunters ecosystem (UNC6240/UNC6661/UNC6671).
The FBI Atlanta Field Office and Indonesian authorities have dismantled the W3LL global phishing platform and arrested its alleged developer. W3LL sold a sophisticated phishing kit designed specifically for bypassing multi-factor authentication on Microsoft 365 accounts using adversary-in-the-middle (AiTM) techniques. The platform operated as a phishing-as-a-service ecosystem with its own marketplace, support channels, and licensing model, enabling thousands of business email compromise campaigns targeting corporate Microsoft 365 environments. This is described as the first coordinated international law enforcement action against this platform. Group-IB previously estimated W3LL's tools had been used to compromise over 8,000 Microsoft 365 business accounts.
A new phishing campaign is hijacking TikTok for Business accounts using adversary-in-the-middle (AITM) reverse proxy pages - meaning it captures credentials, session cookies, and MFA codes in real time. Victims land on cloned TikTok or Google Careers pages after clicking links that redirect through legitimate Google Storage URLs. The real kicker: most users log in via Google SSO, so one compromise gives attackers both TikTok and Google accounts.