Microsoft 365 users hit by two major threat campaigns - fake IT calls and phishing emails target users across the world

https://cdn.mos.cms.futurecdn.net/vnpBJPCcs2siQw5rCEsDzG-2560-80.png
  • Microsoft 365 users targeted by phishing campaigns using BigBear 2.0 and AiTM proxies
  • Attackers impersonate IT staff via calls, Teams, and email to steal credentials and bypass MFA
  • CloudSEK tracked 5,000+ stolen records; Arctic Wolf urges phishing‑resistant MFA and conditional access

Microsoft 365 users are facing a barrage of cyberattacks all aimed at a single goal - to try and expose credentials which can later be used against employers in data theft attacks.

Different groups conduct their raids and bypass multi-factor authentication (MFA) protection to access victim accounts - CloudSEK, for example, said that some groups are using BigBear 2.0, a new phishing-as-a-service (PhaaS) framework that allows crooks to intercept passwords and authenticated session cookies.

Arctic Wolf, on the other hand, focused on a single threat actor, which it dubbed PREY-0058. This group, despite significant overlaps with other collectives in terms of techniques, technologies, and procedures, is not a rebrand...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more