
A wave of cyberattacks across the US and Europe in August exploited the trust businesses place in everyday tools, turning Microsoft 365 logins, remote-management software, and routine business documents into entry points for attackers. Security researchers tracked campaigns that combined account takeover, persistent remote access, and credential theft, often disguised as legitimate activity.
Microsoft 365 Session Hijacking Research from ANY. RUN, highlighted in their August cyberattack analysis, uncovered a phishing operation spanning 46 countries, with nearly half of observed activity tied to the United States. Attackers used fake tax notices, invoices, and shipping documents to trick victims into installing signed remote management tools such as ScreenConnect, ConnectWise, and LogMeIn Rescue.
Because these applications are widely used for legitimate IT support, the malicious activity often blended in with normal administrative traffic, making detection difficult without behavioral analysis. A large-scale phishing-as-a-service kit called Mirage2FA compromised more than 4,000 US victims by intercepting credentials,…
➪ Continue reading the full article on cybersecuritynews.com









