In July 2026, cybercriminals demonstrated a troubling ability to exploit trusted business platforms—such as Microsoft authentication pages, Zoom event invitations, and official government websites—to conduct sophisticated attacks against enterprises. This trend underscores the evolving tactics of attackers who leverage legitimate services to bypass security measures and harvest sensitive information.
Exploitation of Microsoft Authentication and Cloud Services
Attackers have increasingly targeted Microsoft’s authentication mechanisms and cloud services. A notable campaign, identified as Kali365, manipulated Microsoft’s legitimate device-code authentication flow. Victims were directed to authentic Microsoft login pages and prompted to enter attacker-generated authorization codes. This method allowed adversaries to obtain OAuth tokens, granting them persistent access to email archives and shared repositories without needing account passwords. The campaign saw over 80 weekly detections across sectors including manufacturing, healthcare, government, and consulting.
Additionally, the Kratos phishing-as-a-service (PhaaS) platform utilized document-sharing and DocuSign-style lures to funnel Microsoft 365 users through trusted cloud infrastructure toward credential-harvesting pages. By mimicking standard administrative workflows, these attacks successfully bypassed both automated security gateways and human scrutiny.
Abuse of Zoom Events and Government Websites
Cybercriminals expanded their attack vectors by exploiting legitimate Zoom Event pages. They created fake summits branded around prominent tech companies like OpenAI, Anthropic, and Meta. Clicking the “Continue to register” button on these fraudulent events redirected targets to device-code phishing interfaces or adversary-in-the-middle (AiTM) proxies, facilitating credential theft.
In Brazil, the PhantomEnigma campaign compromised over 20 municipal and police web portals (.gov.br domains) to host malware. Hijacked municipal email accounts sent phishing lures that successfully passed SPF, DKIM, and DMARC verification checks, making them appear legitimate to recipients.
Deployment of Advanced Malware
Once initial access was gained, attackers deployed sophisticated malware strains to harvest a wide range of sensitive data. Tools like DestinyStealer collected browser credentials, session cookies, Outlook data, VPN profiles, FileZilla logins, and cryptocurrency wallets. These modular payloads exfiltrated data through parallel HTTP and TCP channels, often evading traditional antivirus detection.
In one observed intrusion, an operator used the OVERLORD Remote Access Trojan (RAT) via a live command-and-control channel. Within 45 minutes, the attacker exfiltrated 86 MB of sensitive files, browser sessions, internal messaging logs, and crypto wallet stores. Variants of Banana RAT introduced randomized file structures and encrypted WebSocket communications, while other campaigns deployed DARTHVADER Stealer through malicious shortcut files using native Windows utilities, AutoIt, and PowerShell script chains.
These developments highlight the increasing sophistication of cyber threats, where attackers exploit the trust associated with legitimate platforms to infiltrate systems. Organizations must enhance their security protocols, including implementing robust multi-factor authentication, conducting regular security awareness training, and monitoring for unusual activity within trusted services. Vigilance and proactive defense strategies are essential to mitigate the risks posed by these evolving attack vectors.