ZeroHour

Search: “evaluation infrastructure”

309 stories

Attackers call employees’ personal phones to break into Microsoft 365 accounts

Microsoft tracks vishing campaigns by Storm-3121 and Storm-3032 that impersonate IT staff, phish Microsoft 365 credentials, and steal cloud data.

Microsoft Security Research has tracked a campaign since May 2026 in which attackers call or text employees' personal phones posing as IT staff, using passkey/MFA/SSO lures to run adversary-in-the-middle phishing or device-code authentication flows. Attackers register their own MFA methods for durable persistence, abuse Microsoft Graph for tenant discovery, and download SharePoint, OneDrive, and Exchange data below 1,000 files or emails per hour to avoid detection. Microsoft attributes initial access to actors including Storm-3121, which feeds ShinyHunters and Falcon extortion operations, and Storm-3032, the Helix extortion operation descended from BlackFile.

Help Net Securityupdated · 18h agofirst · 6d agoPhishing & fraud in the wild 9 sources3

Detect and disrupt AI-themed attacks with Microsoft Defender

Microsoft Threat Intelligence reports criminal campaigns impersonating ChatGPT, Copilot, Claude, and DeepSeek in phishing, AiTM, and malvertising attacks reaching 100,000 emails daily.

Microsoft Threat Intelligence observed a growing set of campaigns that abuse trust in popular AI brands: a ChatGPT-themed phishing campaign sent up to 100,000 emails in one day to steal payment card data, and a Claude-themed campaign used adversary-in-the-middle techniques to harvest credentials and access tokens. Other campaigns included malvertising for a fake AI Windows plugin delivering the Vidar stealer and fraudulent DeepSeek installers distributed via GitHub. Initial access broker Storm-3075 used AI-themed malvertising to distribute payloads for multiple downstream actors, and Microsoft notes the AI services themselves were not compromised. Microsoft also details Defender protections such as Safe Links, Safe Attachments, and attack disruption against these multi-stage lures.

Microsoft Security Blog · 6d agoPhishing & fraud in the wild 2 sources1