tag: Microsoft-365 · 12 items
- Engineer — Plan: AiTM phishing that defeats standard MFA is a config problem, not a patch problem — audit your Entra ID Conditional Access policies and prioritize migrating M365 users to phishing-resistant MFA (FIDO2/passkeys) this quarter, as TOTP and SMS are insufficient against this class of attack.
- SOC/IR — Act: This campaign is active and broadly targeting US enterprises via M365; hunt for AiTM indicators in Entra ID sign-in logs now — flag token issuance from unexpected IPs, session establishment followed by unusual API activity, and impossible-travel events from the same session cookie.
- Leader — Act: With 4,500 organizations targeted and ~48% of targeted addresses potentially compromised, confirm with your team this week that phishing-resistant MFA is enforced for M365 and assess whether your domain appeared in ANY.RUN’s targeting data; this is board-question territory given the scale.
- Engineer — Learn: No exploitation signals or patch action required, but this technique highlights the risk of trusting M365 egress unconditionally; review whether SharePoint/Teams API access from non-user contexts is logged and anomaly-monitored in your environment.
- SOC/IR — Plan: TWINLOOT’s C2-over-SharePoint-Online pattern blends into legitimate M365 traffic — build or tune detections for unusual SharePoint file polling cadence and Teams API calls from non-interactive service contexts to catch implants using this framework.
- Leader — Learn: Newly documented implant class that weaponizes trusted M365 services, useful context for future conversations about M365 security controls and monitoring investment, but no confirmed active campaigns require immediate leadership action.
- Engineer — Plan: Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.
- SOC/IR — Act: Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.
- Leader — Plan: An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.
- Engineer — Plan: AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.
- SOC/IR — Plan: Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.
- Leader — Learn: Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.
- Engineer — Learn: No patch or configuration fix addresses this attack path — it exploits network position, not a software vulnerability. Review M365 Conditional Access policies to enforce device compliance and block legacy auth as a longer-term hardening measure.
- SOC/IR — Act: APT29 campaign with confirmed M365 targeting warrants a hunt for anomalous OAuth token activity and sign-ins from hotel/travel IP ranges since early 2026; tune Conditional Access sign-in logs for impossible-travel or unfamiliar network anomalies and brief on-call on the TTP.
- Leader — Plan: Nation-state targeting of business travelers via hotel networks is a reputational and credential-risk issue worth a travel security advisory this quarter; if your org has frequent international travel, update travel security policy and consider M365 session controls for roaming users.
- Engineer — Skip
- SOC/IR — Skip
- Leader — Plan: The incident underscores M365 concentration risk — review business continuity and failover plans for M365 dependency, and request a resilience briefing from your Microsoft account team this quarter.
- Engineer — Plan: Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.
- SOC/IR — Act: Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.
- Leader — Learn: A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.
- Engineer — Learn: Kratos used adversary-in-the-middle techniques to steal M365 session tokens and bypass MFA — a reminder that TOTP/push-based MFA is insufficient against phishing; engineers should evaluate phishing-resistant MFA (FIDO2/passkeys) for privileged M365 accounts.
- SOC/IR — Learn: No IOCs or detection specifics are provided, so no immediate hunt is actionable; the takedown does validate that AiTM session-token theft against M365 was widespread, which reinforces monitoring for anomalous token reuse and impossible-travel sign-ins if not already covered.
- Leader — Learn: The scale of Kratos confirms that MFA bypass via phishing is not theoretical — useful evidence when making the case for phishing-resistant MFA investment or reviewing identity risk with the board; no immediate action required given the infrastructure has been seized.
- Engineer — Plan: Novel Graph API abuse using calendar write access highlights over-permissioned OAuth app risk. Audit which apps hold Microsoft Graph calendar read/write scopes and revoke unnecessary permissions this quarter.
- SOC/IR — Act: The year-2050 calendar event timestamp is a highly specific, huntable indicator — sweep M365 audit logs for calendar events created with 2050 dates and flag Graph API calls that write calendar entries with large attachments.
- Leader — Learn: Espionage actors using legitimate Microsoft 365 infrastructure for C2 blurs the line between sanctioned SaaS activity and intrusion; useful context for understanding the M365-as-attack-surface risk but no immediate leadership action required.
- Engineer — Learn: Novel living-off-the-land C2 technique abusing legitimate Microsoft Graph calendar APIs to blend into normal M365 traffic; no patch exists but worth reviewing M365 conditional-access and app-permission scopes to limit blast radius of compromised accounts.
- SOC/IR — Plan: Build or tune detection for anomalous Graph API calendar activity (unexpected event creation, unusual read patterns from non-user agents) in M365 audit logs; no published IOCs yet, but the TTP is concrete enough to start a detection rule in Sentinel or Elastic against Graph audit data.
- Leader — Learn: Illustrates how attackers leverage licensed SaaS infrastructure to evade network-level controls; useful context for future budget conversations around M365 audit-log retention and cloud SIEM coverage, but no immediate leadership action required.
- Engineer — Plan: ClickFix is a social-engineering delivery vector, not a patchable vuln — review AppLocker/WDAC policies to restrict arbitrary Run-dialog execution, and audit M365 Conditional Access token-lifetime and revocation settings to limit stolen-session utility.
- SOC/IR — Act: Microsoft Defender Experts documented two active delivery chains; hunt for PowerShell or cmd.exe spawned via user-initiated Run dialog (explorer.exe lineage), and sweep M365 Unified Audit Log for anomalous OAuth grants, bulk file access, or SharePoint/OneDrive exfiltration events since the campaign is live.
- Leader — Plan: Session-token theft bypasses MFA and directly targets M365 documents — worth a leadership brief this quarter on lure-based infostealer risk, and a review of whether security-awareness training covers ClickFix-style social engineering.
- Engineer — Plan: Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.
- SOC/IR — Act: Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.
- Leader — Learn: The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.