<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft-365 on CuraSec</title><link>https://curasec.metacog.co.kr/tags/microsoft-365/</link><description>Recent content in Microsoft-365 on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/microsoft-365/index.xml" rel="self" type="application/rss+xml"/><item><title>Mirage2FA PhaaS Bypasses M365 MFA, 4,500 US/EU Firms Targeted</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-mirage2fa-surge-hits-4-500-us-and-eu-companies-abusing-micro/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM phishing that defeats standard MFA is a config problem, not a patch problem — audit your Entra ID Conditional Access policies and prioritize migrating M365 users to phishing-resistant MFA (FIDO2/passkeys) this quarter, as TOTP and SMS are insufficient against this class of attack.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> This campaign is active and broadly targeting US enterprises via M365; hunt for AiTM indicators in Entra ID sign-in logs now — flag token issuance from unexpected IPs, session establishment followed by unusual API activity, and impossible-travel events from the same session cookie.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> With 4,500 organizations targeted and ~48% of targeted addresses potentially compromised, confirm with your team this week that phishing-resistant MFA is enforced for M365 and assess whether your domain appeared in ANY.RUN&amp;rsquo;s targeting data; this is board-question territory given the scale.&lt;/li>
&lt;/ul></description></item><item><title>TWINLOOT Python Implant Uses SharePoint/Teams for C2</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-twinloot-abuses-sharepoint-and-teams-to-steal-credentials-an/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-twinloot-abuses-sharepoint-and-teams-to-steal-credentials-an/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No exploitation signals or patch action required, but this technique highlights the risk of trusting M365 egress unconditionally; review whether SharePoint/Teams API access from non-user contexts is logged and anomaly-monitored in your environment.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> TWINLOOT&amp;rsquo;s C2-over-SharePoint-Online pattern blends into legitimate M365 traffic — build or tune detections for unusual SharePoint file polling cadence and Teams API calls from non-interactive service contexts to catch implants using this framework.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Newly documented implant class that weaponizes trusted M365 services, useful context for future conversations about M365 security controls and monitoring investment, but no confirmed active campaigns require immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Active AitM Phishing Campaign Hijacks M365 Accounts Targeting Finance</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payr/</link><pubDate>Fri, 07 Aug 2026 11:54:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-microsoft-365-aitm-phishing-hijacks-accounts-to-collect-payr/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Active campaign bypasses MFA via session-token theft on M365 — no KEV or PoC signals, but the exposure is real. Prioritize enforcing phishing-resistant MFA (FIDO2/passkeys) for finance and payroll accounts in Entra ID conditional access policies this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Widespread active campaign with clear TTPs: AitM proxy intercept, residential proxy blend-in, and finance-account targeting. Hunt M365 sign-in logs for logins from residential proxy ASNs, and sweep finance/payroll mailboxes for new unauthorized forwarding rules or OAuth app grants added since the campaign was reported.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> An active, widespread BEC-style campaign harvesting payroll and finance email warrants directing the security team to assess phishing-resistant MFA coverage for high-risk financial roles and briefing finance leadership on social-engineering risk this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Greatness PhaaS expands to AiTM and device-code attacks on M365</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-phishing-service-spoofs-ringcentral-to-steal-microsoft-365-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AiTM and device-code phishing bypass standard MFA; audit your M365 conditional access policies to restrict or block device code flow, and prioritize phishing-resistant MFA (FIDO2 or certificate-based) for privileged accounts this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for suspicious device-code OAuth grant flows and anomalous session token reuse in Entra ID / M365 audit logs — the AiTM component means valid MFA completion is not a reliable innocence signal.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Confirms that commodity phishing platforms are now routing around standard MFA at scale; useful background when justifying a phishing-resistant MFA upgrade on the roadmap or fielding customer security questionnaires about M365 identity controls.&lt;/li>
&lt;/ul></description></item><item><title>APT29 targets hotel Wi-Fi networks to compromise M365 accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-3/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-hotel-wi-fi-attacks-use-custom-malware-to-breach-microsoft-3/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No patch or configuration fix addresses this attack path — it exploits network position, not a software vulnerability. Review M365 Conditional Access policies to enforce device compliance and block legacy auth as a longer-term hardening measure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> APT29 campaign with confirmed M365 targeting warrants a hunt for anomalous OAuth token activity and sign-ins from hotel/travel IP ranges since early 2026; tune Conditional Access sign-in logs for impossible-travel or unfamiliar network anomalies and brief on-call on the TTP.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Nation-state targeting of business travelers via hotel networks is a reputational and credential-risk issue worth a travel security advisory this quarter; if your org has frequent international travel, update travel security policy and consider M365 session controls for roaming users.&lt;/li>
&lt;/ul></description></item><item><title>Hotel Wi-Fi DNS hijacked to phish Microsoft 365 credentials</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accoun/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accoun/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.&lt;/li>
&lt;/ul></description></item><item><title>Microsoft 365 outage caused by automated maintenance bug removing IP routes</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-microsoft-blames-massive-microsoft-365-outage-on-maintenance/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-microsoft-blames-massive-microsoft-365-outage-on-maintenance/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> The incident underscores M365 concentration risk — review business continuity and failover plans for M365 dependency, and request a resilience briefing from your Microsoft account team this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Police Dismantle Kratos MFA-Bypass Phishing Kit; Developer Arrested</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-kit-built-to-steal-microsof/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-police-dismantle-kratos-phishing-kit-built-to-steal-microsof/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Kratos used adversary-in-the-middle techniques to steal M365 session tokens and bypass MFA — a reminder that TOTP/push-based MFA is insufficient against phishing; engineers should evaluate phishing-resistant MFA (FIDO2/passkeys) for privileged M365 accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or detection specifics are provided, so no immediate hunt is actionable; the takedown does validate that AiTM session-token theft against M365 was widespread, which reinforces monitoring for anomalous token reuse and impossible-travel sign-ins if not already covered.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The scale of Kratos confirms that MFA bypass via phishing is not theoretical — useful evidence when making the case for phishing-resistant MFA investment or reviewing identity risk with the board; no immediate action required given the infrastructure has been seized.&lt;/li>
&lt;/ul></description></item><item><title>HollowGraph malware abuses M365 calendar as C2 channel</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel living-off-the-land C2 technique abusing legitimate Microsoft Graph calendar APIs to blend into normal M365 traffic; no patch exists but worth reviewing M365 conditional-access and app-permission scopes to limit blast radius of compromised accounts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detection for anomalous Graph API calendar activity (unexpected event creation, unusual read patterns from non-user agents) in M365 audit logs; no published IOCs yet, but the TTP is concrete enough to start a detection rule in Sentinel or Elastic against Graph audit data.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates how attackers leverage licensed SaaS infrastructure to evade network-level controls; useful context for future budget conversations around M365 audit-log retention and cloud SIEM coverage, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>HollowGraph Malware Uses M365 Calendar Events Dated 2050 as C2 Channel</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-3/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-hollowgraph-malware-hides-c2-and-stolen-files-in-microsoft-3/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Novel Graph API abuse using calendar write access highlights over-permissioned OAuth app risk. Audit which apps hold Microsoft Graph calendar read/write scopes and revoke unnecessary permissions this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> The year-2050 calendar event timestamp is a highly specific, huntable indicator — sweep M365 audit logs for calendar events created with 2050 dates and flag Graph API calls that write calendar entries with large attachments.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Espionage actors using legitimate Microsoft 365 infrastructure for C2 blurs the line between sanctioned SaaS activity and intrusion; useful context for understanding the M365-as-attack-surface risk but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>ACR Stealer ClickFix Campaign Targets M365 Sessions and Browser Credentials</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-acr-stealer-uses-clickfix-lures-to-steal-browser-tokens-and/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-acr-stealer-uses-clickfix-lures-to-steal-browser-tokens-and/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> ClickFix is a social-engineering delivery vector, not a patchable vuln — review AppLocker/WDAC policies to restrict arbitrary Run-dialog execution, and audit M365 Conditional Access token-lifetime and revocation settings to limit stolen-session utility.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft Defender Experts documented two active delivery chains; hunt for PowerShell or cmd.exe spawned via user-initiated Run dialog (explorer.exe lineage), and sweep M365 Unified Audit Log for anomalous OAuth grants, bulk file access, or SharePoint/OneDrive exfiltration events since the campaign is live.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Session-token theft bypasses MFA and directly targets M365 documents — worth a leadership brief this quarter on lure-based infostealer risk, and a review of whether security-awareness training covers ClickFix-style social engineering.&lt;/li>
&lt;/ul></description></item><item><title>Exposed Server Leaks Three Evilginx M365 Phishing Operations</title><link>https://curasec.metacog.co.kr/insights/2026-07-13-misconfigured-server-reveals-three-evilginx-phishing-operati/</link><pubDate>Mon, 13 Jul 2026 13:18:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-13-misconfigured-server-reveals-three-evilginx-phishing-operati/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Evilginx bypasses TOTP-based MFA by proxying credentials; if your M365 tenant uses authenticator-app OTP rather than FIDO2/hardware keys, plan migration to phishing-resistant MFA and enforce Entra ID Conditional Access requiring compliant devices this quarter.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Three live AiTM operations were exposed with their full toolkits; pull the IOCs Lexfo published, sweep M365/Entra ID sign-in logs for unfamiliar token-issuing IP ranges, and tune detections for impossible-travel or session-token reuse patterns since AiTM bypasses MFA alerts entirely.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> The exposure of three concurrent industrial-scale M365 phishing operations illustrates why TOTP MFA is insufficient as a control; useful context when building the case for phishing-resistant MFA investment in the next budget cycle.&lt;/li>
&lt;/ul></description></item></channel></rss>