A look inside three Microsoft 365 phishing operations
Lexfo has published research on three Microsoft 365 phishing operations exposed through an open directory on an attacker-controlled server. The researchers recovered Evilginx-derived tooling, phishing configurations, credential logs, Telegram artifacts and operator files, and linked the tooling to both adversary-in-the-middle phishing and OAuth device-code phishing. One device-code campaign had 218 identified victims across 12 countries, with roughly 94 percent of the captured accounts belonging to corporate mailboxes.
What this means for your organisation
The critical point is that these techniques bypass multi-factor authentication. The attacker sits between the user and Microsoft and captures the session after the user has done everything correctly. Device-code phishing is more uncomfortable still, because the user authenticates on a genuine Microsoft page and hands over access anyway. That 94 percent of victims were corporate accounts says something about the targeting. This is not indiscriminate mass mail.
Berigo recommends
- Roll out phishing-resistant multi-factor authentication based on passkeys or certificates for users with access to sensitive information.
- Block or restrict device code sign-in in Entra ID where there is no documented need.
- Apply conditional access that ties the session to a managed device, so a stolen session cookie alone is not sufficient.
- Monitor for sign-ins with unusual location and device combinations, and have a routine for revoking active sessions quickly.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch