ZeroHour

Search: “missing authentication”

94 items

Inside Knight Office, a New M365 AiTM Phishing Kit

Huntress details Knight Office, a new AiTM phishing kit stealing Microsoft 365 session tokens and registering attacker-controlled devices.

Huntress investigated an August 18, 2026 adversary-in-the-middle attack using the Knight Office phishing kit, which captured Microsoft 365 session tokens via a DocuSign-style lure routed through a Monday.com tracking link and a compromised Joomla site. After token capture, the actor enrolled an unauthorized host in Microsoft Entra ID and bound a Windows Hello for Business key credential to the account. The kit's operator console, found at IP 104.37.188.94, is built on Python Flask and hosts at least 25 .vu phishing domains. Telemetry links the kit to at least nine token-replay logins in two weeks and roughly 700 reported lure emails since April.

Huntress · 15d agoPhishing & fraud in the wild1

New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

ANY.RUN researchers uncovered the N0va phishkit targeting government, technology, consulting, and healthcare organizations across North America and the EU via device code phishing.

The N0va phishkit uses lures imitating Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, Dropbox, Zoom, and Adobe Sign to draw victims into a device code authentication flow. After the user completes legitimate authentication, N0va captures access and refresh tokens and abuses token-exchange and device-registration mechanisms to establish persistent SSO access to corporate resources. Because the flow relies on real Microsoft authentication, it can evade MFA-focused detections, and token access can outlive takedown of the phishing page. ANY.RUN says it observed the campaign in sandbox sessions, with targeting spanning government, technology, consulting, and healthcare sectors.

Cyber Security News · 7d agoPhishing & fraud in the wild1

PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks

PAPERMILL phishing campaign abuses a signed Notepad++ copy and tax-audit lures to deploy VenomRAT against targets in India.

JUMPSEC tracks PAPERMILL as an emerging cluster whose emails pass SPF, DKIM, and DMARC and deliver tax-audit themed disk images. The mounted image pairs a legitimately signed, renamed executable with a rogue libcurl.dll for DLL sideloading, then uses a Donut shellcode loader to run VenomRAT 6.0.3 in memory with hidden VNC, data-stealing, and file-grabbing capabilities. The loader includes anti-analysis checks and RunOnce persistence, and lures plus China-connected infrastructure overlap with the Silver Fox ecosystem, though attribution remains unconfirmed.

Cyber Security News · 1d agoPhishing & fraud in the wild 2 sources

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Unit 42 details 'Spring Ring', a vishing campaign using fake IT support on Microsoft Teams to reach 150+ employees at 10+ companies.

Palo Alto Networks Unit 42 documented 'Spring Ring', a voice-phishing campaign that ran January to April 2026, using 26 attacker identities and fake Microsoft 365 tenants such as 'ITProtectionDepartment' to impersonate internal IT support on Microsoft Teams. One path used Quick Assist or downloaded remote-support tools to run an obfuscated PowerShell script that disabled malware scanning before contacting C2; the other delivered a cloud-hosted file triggering browser hijacking, SMB internal network scanning, and a PetitPotam NTLM relay attempt against domain controllers to gain domain-level privileges. Both intrusion attempts were blocked before attackers reached their objectives. Collaboration-platform phishing alerts rose to 42% of Unit 42's telemetry in early 2026, up from 30%.

Help Net Security · 16d agoPhishing & fraud in the wild1