In August 2026, attackers launched coordinated campaigns across the United States and Europe targeting organizations through Microsoft 365 session hijacking, abuse of remote management software (RMM), and advanced phishing tactics. These operations exploited everyday tools and documents familiar to businesses to bypass defenses and take control of corporate access. Recent research has exposed how these schemes subvert both multi-factor authentication (MFA) and trusted IT support platforms.
Key Attack Methods & Tools Employed
One major vector involved phishing lures disguised as tax notices, invoices, or shipping documents. These were used to trick victims into installing signed RMM tools such as ScreenConnect, ConnectWise, and LogMeIn Rescue. Because these applications are par for the course in legitimate IT service operations, their misuse often flew under the radar without behavioral analytics in place. This type of RMM abuse helped attackers secure persistent remote access into compromised environments.
Another core threat was the Mirage2FA service kit, designed as a phishing-as-a-service (PaaS) offering. It employed adversary-in-the-middle techniques to steal credentials, session cookies, and one-time codes, letting attackers hijack Microsoft 365 sessions even after victims completed MFA. More than 4,000 U.S. victims were compromised this way, with sensitive assets including email, cloud storage, and financial data at risk.
Additional tools heightened the severity of attacks. SnakeBiteAgent, a .NET-based remote access trojan, was delivered via business-themed ZIP files. Once installed, it enabled credential theft, keylogging, webcam monitoring, and surreptitious AnyDesk installs. Phishing kits like 3DBlast used browser-in-the-browser setups, OAuth device-code phishing, and live session relay to impersonate Microsoft 365 or Google login pages. These kits rotated infrastructure to avoid detection by static defenses.
Finally, researchers uncovered a group labeled Famous Chollima, allegedly linked to Lazarus. They used false identities to pass remote job-screening checks at staged DeFi startups, gaining access to internal codebases and systems. These operations often targeted education, manufacturing, and technology organizations.
Recommendations for Defense
Security teams are urged to go beyond password resets when responding to Microsoft 365 hijackings. Since stolen sessions can stay active even after resets, revoking tokens and monitoring unusual RMM usage or tool installations is critical. Identity verification for remote employees should be tougher, while deployment of phishing-resistant MFA helps block adversary-in-the-middle fraud.
Behavioral threat intelligence is essential for spotting rotating infrastructure and belated phishing campaigns. Examining suspicious documents, URLs, and attachments through sandbox environments or interactive analysis can uncover hidden risks before they become breaches. Organizations are also encouraged to beef up enterprise defenses using these tools to reduce exposure.
The latest wave of attacks marks a shift in how threat actors are abusing legitimate tools and infrastructure to carry out session hijacking across Microsoft 365 environments. Instead of relying on classic malware pushes, they’re exploiting trust and process to slip past defenses and gain long-term footholds.
Analysis: These developments signal a dangerous evolution in business-targeted cybercrime. Attackers are no longer simply trying to brute-force access—they’re leveraging tools and tactics organizations use daily. The reliance on signed RMM software and the effective evasion of MFA via AiTM kits demonstrate how layered defenses are being undermined. For defenders, protecting identity tokens and active sessions is now as crucial as defending perimeters or managing credentials. Watch for vendors raising the bar on MFA and for threat intel that spots changes in attacker infrastructure early, because in this new landscape, speed and context matter more than ever.